Russia Hacked Routers to Steal Microsoft Office Tokens
2026-04-12T01:23:37Z•9a4cde54ed149484db3850e79cd99ed19a47b6edde70840bf362caf491c48e4c
AisuruCanisterWormDDoSGandCrabI2PIoT-botnetIranJackSkidKimwolfMFA-bypassMicrosoft-OfficeMossadREvilRussiaStarkillerStrykerauthentication-tokenscredential-theftdoxingmilitary-intelligencephishing-as-a-serviceransomwareroutersvulnerabilities','patch-tuesday','AI-assistants'wiper
What happened
Multiple high-impact cyber incidents and trends: Russia-linked military intelligence operators exploited known flaws in older Internet routers to mass-harvest Microsoft Office authentication tokens from users on more than 18,000 networks without deploying malware. Separately, German authorities identified and doxxed Daniil Shchukin as the operator “UNKN” behind REvil/GandCrab; an Iran-targeted worm called CanisterWorm is spreading via weak cloud deployments and wiping systems with Iran/Farsi settings; and an Iran-linked group claimed a wiper attack against medical device firm Stryker. Law-enf/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 9a4cde54ed149484db3850e79cd99ed19a47b6edde70840bf362caf491c48e4c
- Enrichment time
- 2026-04-12T01:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.