Last Update: 08/01/2026 at 2:00 PM EST

Hackers Target Microsoft 365 Credentials

Coverage from BleepingComputer, CNET, and others

Articles

5

Active Days

109

The Topic

Hackers Target Microsoft 365 Credentials topic image

Threat actors are targeting Microsoft 365 identities through two complementary paths: APT28 has redirected authentication traffic by compromising vulnerable SOHO routers, while a separate campaign used exposed credentials and the Azure CLI to conduct large-scale password spraying. The activity shows how attackers can obtain account access or tokens by exploiting weak edge-device security, legacy authentication flows, incomplete MFA policies, and reused credentials. Law-enforcement disruption has removed some infrastructure, but affected organizations and users still need to patch or replace exposed routers and strengthen identity controls.

First Article: 04/07/26

Latest Article: 07/24/26

Summary

  • APT28 altered DNS settings on vulnerable MikroTik and TP-Link SOHO routers to redirect Microsoft 365 authentication traffic through attacker-controlled infrastructure.
  • The FrostArmada operation reached about 18,000 devices across 120 countries at its December 2025 peak and affected government, law-enforcement, hosting, and other organizations.
  • Adversary-in-the-middle infrastructure intercepted Microsoft authentication traffic and OAuth tokens, including after users completed MFA.
  • A separate password-spraying campaign generated more than 81 million Microsoft 365 login attempts and compromised 78 accounts across 64 organizations.
  • The password-spraying activity exploited valid credentials from earlier breaches and used the Azure CLI's ROPC flow, which bypassed MFA where Conditional Access policies did not cover it.
  • The router campaigns relied heavily on unpatched or end-of-life equipment and unchanged default passwords, leaving remediation dependent on device owners.
  • The FBI, U.S. Department of Justice, Microsoft, Lumen's Black Lotus Labs, and Polish authorities disrupted parts of the APT28 infrastructure, but disruption did not repair affected devices.

History

07/23/2026

The update adds a clearer operational detail on the router-hijacking side and expands the response story: the APT28 campaign is now tied to a named operation and confirmed disruption by additional authorities, while remediation is framed as still incomplete. The separate password-spraying campaign is largely unchanged.

07/21/2026

The story broadened from a single APT28 router-hijacking operation into a wider set of Microsoft 365 credential attacks, including a separate large-scale password-spraying campaign that succeeded despite MFA gaps. It also adds more precise scale, timing, and affected-organization details, making the identity-policy weaknesses more prominent.

Featured

Timeline: 109 Days

Apr 7Apr 28May 19Jun 9Jun 30Jul 21

Additional Articles

⭐⭐⭐⭐⭐

BleepingComputer / Bill Toulas04-07-2026
Microsoft and Black Lotus Labs report that APT28 used router-based DNS hijacking and AiTM in FrostArmada during 2025, stealing Microsoft credentials and OAuth tokens.
Krebs on Security / Brian Krebs04-07-2026
Microsoft and Lumen reported that Russia-backed Forest Blizzard used DNS hijacking on 18,000 vulnerable SOHO routers during December 2025 to intercept OAuth tokens from Microsoft users.