Authorities Stop Router Hacks Targeting Microsoft 365 Logins


Soho DNS Router Hijacks Microsoft 365

Law enforcement agencies recently shut down a major hacking operation that targeted home and small office networks. The attackers compromised insecure internet routers to secretly redirect network traffic and steal login details. Microsoft confirmed the attackers focused on grabbing access to Microsoft 365 accounts.

The tech company tied the operation to a Russian military group known as Forest Blizzard. This disruption stops a widespread threat that puts countless remote workers at risk.

Here’s how the hijacked routers worked

The hackers did not attack computers directly. They scanned the internet for vulnerable home and small business routers that had weak passwords or outdated software. Once they broke into a specific device, they changed its internal settings. They specifically altered the Domain Name System rules. 

When users connected to the compromised router and typed in a web address to access Microsoft 365, the hardware sent them to a fake login page instead. The redirection happened so smoothly that the victims noticed nothing unusual.

Because the fake website looked exactly like the real thing, people typed in their usernames and passwords without suspecting a problem. The attackers used a tactic called adversary in the middle. This setup allowed them to steal the login information in real time.

They even managed to grab the special security tokens generated by multifactor authentication systems. With those tokens, the hackers could freely log into the actual Microsoft 365 accounts of the victims, read their emails, and access sensitive files.

Microsoft has disabled the servers receiving the stolen data

Microsoft worked alongside international authorities to spot the malicious infrastructure and shut it down completely. Security teams disabled the servers receiving the stolen information and blocked the fake websites the hackers built to trick users. The joint operation successfully cut off the ability of Forest Blizzard to intercept new login attempts across the globe.

While the immediate threat is gone, security experts warn that people still need to fix their home equipment. If you use a basic router provided by your internet company or bought one from a store years ago, you should check for software updates. You also need to replace the default administrative password with something secure.

Companies are advising their remote workers to reboot their routers and watch out for strange login requests. Taking a few minutes to secure the hardware connecting your home to the internet stops these types of attacks from happening again.

Via BeepingComputers

More about the topics: microsoft, Windows 11

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages