[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYijMoNZ_DP22isb-0sWHH1VDwRFk63XYm2oFdFhIHKA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"dec266b8-85e0-4088-b7ab-4c989d66052f","russian-apt28-exploits-unpatched-soho-routers-to-steal-oauth-tokens","c6514cf8-86cb-4fed-90f4-02aafd4bd84d","Russian APT28 Exploits Unpatched SOHO Routers to Steal OAuth Tokens","Russian GRU hackers exploited known vulnerabilities in older small office\u002Fhome office routers to manipulate DNS settings and intercept Microsoft Office authentication tokens from over 18,000 networks. By redirecting DNS queries, attackers performed man-in-the-middle attacks on TLS connections without deploying traditional malware, compromising over 200 organizations and 5,000 consumer devices. This demonstrates how neglected network infrastructure can become a gateway for sophisticated nation-state attacks targeting critical authentication systems.","**Immediate actions:**\n- Update all SOHO routers and network appliances to the latest firmware versions\n- Scan all internet-facing devices for known vulnerabilities using automated tools\n- Verify DNS settings on all network devices match organizational policies\n\n**Long-term improvements:**\n- Establish automated patch management processes for all network infrastructure\n- Maintain a comprehensive inventory of all network appliances including SOHO devices\n- Implement network segmentation to isolate critical authentication services\n\n**Detection measures:**\n- Monitor DNS queries for suspicious redirections or unauthorized changes\n- Deploy network traffic analysis to detect man-in-the-middle attack patterns",[12,13,14,15,16,17],"CIS Control 7","CIS Control 12","NIST CM-3","NIST SI-2","NIST RA-5","ISO 27001 A.12.6.1","published","2026-04-07T19:08:57.717391+00:00","2026-04-07T19:08:57.617+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F04\u002Frussia-hacked-routers-to-steal-microsoft-office-tokens\u002F","russia-hacked-routers-to-steal-microsoft-office-tokens","Russia Hacked Routers to Steal Microsoft Office Tokens",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]