[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKsFnisrvRIxuLNuUjlePw6cG1z8cv2S_Ci-WhaP41ds":3},{"article":4,"iocs":47,"watch_terms":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":31},"c6f13cf7-167c-431c-bc66-bfb3f9513c1c","Russia's Forest Blizzard Nabs Rafts of Logins Via SOHO Routers","russia-s-forest-blizzard-nabs-rafts-of-logins-via-soho-routers-27aef7","Heard of fileless malware? How about malwareless cyber espionage? Russia's APT28 is spying on global organizations by modifying just one DNS setting in vulnerable routers.","Russia's APT28 threat group, operating under the Forest Blizzard campaign, is conducting large-scale cyber espionage by exploiting vulnerabilities in SOHO routers to modify DNS settings without deploying traditional malware. The technique enables DNS hijacking to intercept login credentials from targeted organizations globally. This fileless approach complicates detection and represents a shift toward infrastructure-level compromise rather than endpoint-focused attacks.","APT28 conducts DNS hijacking via SOHO router vulnerabilities for credential theft.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fthreat-intelligence\u002Frussia-forest-blizzard-logins-soho-routers","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt6f8022c4798db6b6\u002F69d6c0b5f017ad2a52b62767\u002Fforest_blizzard-Lukas_Jonaitis-alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-04-09T01:00:00+00:00","2026-04-09T02:00:22.93194+00:00",8,[18,21,24],{"name":19,"type":20},"APT28","threat_actor",{"name":22,"type":23},"Forest Blizzard","campaign",{"name":25,"type":26},"SOHO routers","technology","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":27,"icon":11,"name":29,"slug":30},"Nation-state","nation-state",[32,37,42],{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":43},{"id":44,"icon":11,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[]]