Hackers Target Microsoft 365 Credentials
Coverage from BleepingComputer, CNET, and others
Articles
5
Active Days
109
The Topic

Threat actors are targeting Microsoft 365 identities through two complementary paths: APT28 has redirected authentication traffic by compromising vulnerable SOHO routers, while a separate campaign used exposed credentials and the Azure CLI to conduct large-scale password spraying. The activity shows how attackers can obtain account access or tokens by exploiting weak edge-device security, legacy authentication flows, incomplete MFA policies, and reused credentials. Law-enforcement disruption has removed some infrastructure, but affected organizations and users still need to patch or replace exposed routers and strengthen identity controls.
First Article: 04/07/26
Latest Article: 07/24/26
Summary
- APT28 altered DNS settings on vulnerable MikroTik and TP-Link SOHO routers to redirect Microsoft 365 authentication traffic through attacker-controlled infrastructure.
- The FrostArmada operation reached about 18,000 devices across 120 countries at its December 2025 peak and affected government, law-enforcement, hosting, and other organizations.
- Adversary-in-the-middle infrastructure intercepted Microsoft authentication traffic and OAuth tokens, including after users completed MFA.
- A separate password-spraying campaign generated more than 81 million Microsoft 365 login attempts and compromised 78 accounts across 64 organizations.
- The password-spraying activity exploited valid credentials from earlier breaches and used the Azure CLI's ROPC flow, which bypassed MFA where Conditional Access policies did not cover it.
- The router campaigns relied heavily on unpatched or end-of-life equipment and unchanged default passwords, leaving remediation dependent on device owners.
- The FBI, U.S. Department of Justice, Microsoft, Lumen's Black Lotus Labs, and Polish authorities disrupted parts of the APT28 infrastructure, but disruption did not repair affected devices.
History
The update adds a clearer operational detail on the router-hijacking side and expands the response story: the APT28 campaign is now tied to a named operation and confirmed disruption by additional authorities, while remediation is framed as still incomplete. The separate password-spraying campaign is largely unchanged.
The story broadened from a single APT28 router-hijacking operation into a wider set of Microsoft 365 credential attacks, including a separate large-scale password-spraying campaign that succeeded despite MFA gaps. It also adds more precise scale, timing, and affected-organization details, making the identity-policy weaknesses more prominent.
