Russia Hacked Routers to Steal Microsoft Office Tokens

2026-04-10T13:23:37Z9241dc3f8373d6a6d0f0723a8ee1edc6eda740d7dad96d98487127329c259c39
AisuruCanisterWormDDoSDaniil ShchukinGandCrabJackSkidKimwolfMossadREvilStarkiller phishing serviceStrykerUNKNauthentication token theftcloud misconfigurationdoxingiot botnetiran-backediran-targetedmicrosoft office tokensmicrosoft vulnerabilitiespatch tuesdayphishing-as-a-servicerouter compromiserussian state-backedwiper

What happened

Multiple high-impact incidents and research briefs: Russian state-linked hackers exploited known vulnerabilities in older home/ISP routers to harvest Microsoft Office authentication tokens from users on over 18,000 networks without deploying malware. German authorities publicly identified Daniil Maksimovich Shchukin (aka “UNKN”) as the alleged leader of GandCrab/REvil linked to numerous extortion incidents. A financially motivated group deployed ‘CanisterWorm,’ a worming wiper that spreads via poorly secured cloud services and targets systems using Iran time zone or Farsi locale. U.S., Canada,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
9241dc3f8373d6a6d0f0723a8ee1edc6eda740d7dad96d98487127329c259c39
Enrichment time
2026-04-10T13:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russia Hacked Routers to Steal Microsoft Office Tokens · Baitaphish