Russia Hacked Routers to Steal Microsoft Office Tokens
2026-04-14T07:23:33Z•542208dc217fb3c290e5a5e7b576c3f1c6c2c818653ab752d3d60584dbac9a99
AisuruCanisterWormDDoSGandCrabIoT-botnetIranJackSkidKimwolfMFA-bypassMicrosoft OfficeMossadREvilRussiaStarkillerStrykerauthentication-tokensdoxinglaw-enforcement-takedown','Patch-Tuesday','vulnerabilities','mspnation-statephishing-as-a-serviceransomwarerouter-exploittoken-theftwiperwiper-attack
What happened
Multiple high-impact cyber incidents and trends: Russian military-linked actors exploited known vulnerabilities in older consumer routers to mass-harvest Microsoft Office authentication tokens from over 18,000 networks without deploying malware. A new phishing-as-a-service called “Starkiller” proxies real login pages and relays credentials and MFA codes to bypass MFA protections. Large IoT botnets (Kimwolf, Aisuru, JackSkid, Mossad) have been implicated in record DDoS campaigns and recent law-enforcement actions disrupted their infrastructure; Kimwolf also overwhelmed the I2P anonymity network
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 542208dc217fb3c290e5a5e7b576c3f1c6c2c818653ab752d3d60584dbac9a99
- Enrichment time
- 2026-04-14T07:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.