
Published: April 10, 2026
For years, identity security was treated as something that began at the login prompt. But identity risk in compromised routers is now becoming a real enterprise security problem. Users reached Microsoft 365, Entra ID, VPNs, and SaaS platforms, and only then did defenders evaluate risk, enforce MFA, or block suspicious access. That assumption is getting weaker. A newly detailed campaign tied to Russia-linked Forest Blizzard shows how compromised small-office and home-office routers can be used to alter DNS settings upstream, quietly placing the attacker in the path before identity controls ever come into play.
Microsoft reported on April 7, 2026, that Forest Blizzard—a threat actor linked to the Russian military—has, since at least August 2025, carried out large-scale exploitation of vulnerable SOHO devices to hijack DNS requests and support follow-on adversary-in-the-middle (AiTM) activity. Microsoft identified more than 200 organizations and over 5,000 consumer devices affected, spanning government, IT, telecommunications, and energy sectors.
The broader government warning adds context. The FBI, IC3, and DOJ noted that GRU actors (also tracked as APT28, Fancy Bear, and Forest Blizzard) have been exploiting vulnerable routers since at least 2024, including TP-Link devices affected by CVE-2023-50224. They modified DHCP and DNS settings so connected systems inherit actor-controlled resolvers. The DOJ stated the campaign involved compromised routers facilitating DNS hijacking against targets of intelligence interest to the Russian government. In early April 2026, the DOJ and FBI disrupted the U.S. portion of the malicious DNS network in an operation called Masquerade.
This distinction matters. The campaign was not simply about compromising routers for persistence. It was about using them as upstream control points. Once the DNS path changed, laptops, phones, and other devices on the same network could send DNS requests through attacker-controlled infrastructure—without the user installing malware or the endpoint itself being directly compromised.
The real lesson is not about one router vendor or one exploit. It is that identity defenses increasingly depend on network paths organizations do not control well. Remote and hybrid work mean employees authenticate from home networks, branch offices, and small unmanaged environments where routers may be outdated, exposed, or rarely monitored. Microsoft explicitly warned that compromised SOHO infrastructure can expose cloud access and sensitive data even when enterprise environments and cloud services themselves remain secure.
This creates a blind spot for defenders who think in neat layers: device, identity, application. In this campaign, DNS manipulation happened before Conditional Access, sign-in risk evaluation, or many traditional monitoring controls had a chance to intervene. The endpoint might look healthy. The identity stack might be configured correctly. But if the client is guided by malicious resolver settings inherited through DHCP, the user’s path to a trusted service is already degraded.
In short, the authentication path can be compromised before authentication is even evaluated. Hybrid work has effectively extended the identity perimeter to every kitchen table and home office router—networks that organizations rarely inventory or harden.
| Threat Type | SOHO Router DNS Hijacking + Selective Adversary-in-the-Middle (AiTM) on Authentication Traffic |
|---|---|
| Severity | High – Nation-state actor using consumer routers as upstream identity attack vector; low cost to attacker, difficult to detect at scale |
| Active Campaigns | Forest Blizzard (APT28 / GRU-linked) – Ongoing since at least August 2025, with related activity since 2024 |
| High-Risk Exposure | Remote/hybrid workers authenticating from unmanaged home or SOHO networks; Outlook on the web and other cloud identity services |
| Exploitation Status | Actively used in targeted operations; U.S. portion of malicious DNS infrastructure disrupted in April 2026 |
| Mitigation Availability | Partial – Firmware updates, secure DNS enforcement, phishing-resistant MFA, and better correlation between identity and network telemetry |
The router has become part of the identity attack path. Instead of targeting the enterprise directly, Forest Blizzard compromised vulnerable small-office and home-office routers to hijack DNS resolution upstream of authentication. This allows the attacker to sit silently in the path to cloud identity providers without ever touching the corporate network or installing endpoint malware.
The campaign demonstrates how unmanaged edge infrastructure—especially consumer routers used by remote workers—can silently undermine even well-configured identity systems like Entra ID and Conditional Access.
Defensive Maturity Note: Most organizations still treat DNS and home routers as “someone else’s problem.” This campaign shows they have become critical components of the modern identity perimeter.
Forest Blizzard’s campaign demonstrates how cheaply and effectively attackers can position themselves upstream of enterprise authentication by compromising everyday routers. The network path to identity is no longer neutral—it is now a high-value attack surface.
Harden edge devices today, enforce secure resolvers and path validation tomorrow, and redesign identity policies to assume the route itself may be hostile. The time to treat the router as part of the identity attack surface is now—before the next set of stolen credentials is used against you.
If you find ByteVanguard useful, you can support the site and help keep the analysis independent.
Support the analysis