APT28 FrostArmada DNS hijacking and AitM credential theft campaign
Campaign
Summary
Hide ▲
Show ▼
A multinational disruption effort has taken down FrostArmada, an APT28 campaign that hijacked router DNS settings to steal Microsoft account credentials and OAuth tokens. The operation abused MikroTik and TP-Link routers, then funneled authentication traffic through attacker-controlled VPS nodes for adversary-in-the-middle (AitM) collection. At its peak in December 2025, it infected 18,000 devices across 120 countries and targeted government, law enforcement, IT, hosting, and self-hosted server operators.
Related Happenings
Russian FSB Center 16 router intrusion campaign
Campaign
H score40
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Russian FSB Center 16 router intrusion campaign
CampaignAbout this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Balochistan Police hit by network compromise
Incident
H score25
First: 11.07.2026 20:49
Last: 11.07.2026 20:49
Sources 1
About this happening:
Balochistan Police suffered a long-running compromise of police infrastructure and a public-facing Complaint Management System (CMS), with exposure spanning June 2,...
Balochistan Police hit by network compromise
IncidentAbout this happening: Balochistan Police suffered a long-running compromise of police infrastructure and a public-facing Complaint Management System (CMS), with exposure spanning June 2,...
Operation Endgame takedown of SocGholish and Evil Corp infrastructure
Law Enforcement
H score58
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
About this happening:
International law enforcement disrupted SocGholish/FakeUpdates infrastructure in Operation Endgame on June 18, cleaning 14,971 compromised WordPress websites a...
Operation Endgame takedown of SocGholish and Evil Corp infrastructure
Law EnforcementAbout this happening: International law enforcement disrupted SocGholish/FakeUpdates infrastructure in Operation Endgame on June 18, cleaning 14,971 compromised WordPress websites a...
Secret Blizzard Kazuar modular P2P botnet
Malware Activity
H score28
First: 16.05.2026 17:15
Last: 16.05.2026 17:15
Sources 1
About this happening:
Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Secret Blizzard Kazuar modular P2P botnet
Malware ActivityAbout this happening: Kazuar is being used in a multi-stage campaign in Ukraine that ESET says likely involves Gamaredon providing access and Turla/Secret Blizzard delivering the ba...
Brazilian ISP botnet DDoS campaign
Campaign
H score36
First: 30.04.2026 17:04
Last: 30.04.2026 17:04
Sources 1
About this happening:
The Brazilian ISP botnet DDoS campaign has been linked to a Brazil-based threat actor that repeatedly hit Brazilian network operators over several years. The operation...
Brazilian ISP botnet DDoS campaign
CampaignAbout this happening: The Brazilian ISP botnet DDoS campaign has been linked to a Brazil-based threat actor that repeatedly hit Brazilian network operators over several years. The operation...
Timeline
-
07.04.2026 18:51 2 articles · 3mo ago
FrostArmada disruption and router DNS hijack disclosure
Initial DisclosureLaw enforcement and private-sector partners disrupted FrostArmada, an APT28 campaign that compromised internet-exposed MikroTik and TP-Link routers, rewrote DNS settings to attacker-controlled VPS resolvers, and used adversary-in-the-middle proxies to steal Microsoft logins and OAuth tokens. The campaign targeted Microsoft 365-related domains and had reached 18,000 infected devices across 120 countries at its December 2025 peak before the offending infrastructure was taken offline.
Show sources
- Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins — www.bleepingcomputer.com — 07.04.2026 18:51
- Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins — www.bleepingcomputer.com — 07.04.2026 18:51