Russia Hacked Routers to Steal Microsoft Office Tokens

2026-04-11T01:23:37Z8fce8cda8b658750cde4f2bf204f89e28283e1868b99fc52bace493b47f75f70
AisuruCanisterWormDDoSDaniil ShchukinGandCrabI2P disruptionIoT botnetIran-linked actorsJackSkidKimwolfMFA bypassMicrosoft Office tokensMicrosoft Patch Tuesday March 2026 (77 fixes)」「AI assistants (thMossadOAuth token theftREvilRussia-linked actorsStarkillerStrykerauthentication-token theftcredential relaydoxxingphishing-as-a-servicerouter exploitwiper malware

What happened

A collection of high-impact cyber incidents and trends: Russian military-linked actors exploited known vulnerabilities in older consumer/ISP routers to mass-harvest Microsoft Office authentication tokens from over 18,000 networks; German authorities identified and doxxed Daniil Maksimovich Shchukin (“UNKN”), alleged head of GandCrab and REvil; a worm dubbed “CanisterWorm” targets Iranian systems via poorly secured cloud services and performs destructive wiping based on timezone/Farsi settings; an Iran-linked group claims responsibility for a wiper hit on medtech firm Stryker. Law enforcement (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
8fce8cda8b658750cde4f2bf204f89e28283e1868b99fc52bace493b47f75f70
Enrichment time
2026-04-11T01:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.