Russia Hacked Routers to Steal Microsoft Office Tokens
2026-04-09T01:23:32Z•e3aa68e6875cabfdc776fde8bad7b45b7169ba653c0215e9e59be3036564fc4f
AI assistantsAisuruCanisterWormDDoSGandCrabIoT botnetIranJackSkidKimwolfMFA bypassMicrosoft OfficeMicrosoft Patch TuesdayMossadREvilRussiaStarkillerStrykerauthentication tokensdoxingnation-statepatch-managementphishing-as-a-serviceransomwarerouter vulnerabilitieswiper
What happened
Multiple high-impact cyber incidents and trends: Russian military-linked actors exploited known flaws in legacy routers to mass-harvest Microsoft Office authentication tokens from over 18,000 networks without installing malware; German authorities identified “UNKN” as Daniil Shchukin, linking him to REvil and GandCrab ransomware campaigns; an extortion group unleashed the CanisterWorm wiper that spreads via misconfigured cloud services and targets systems using Iran time zone or Farsi; Iran-linked actors claimed a wiper attack against medical device firm Stryker; U.S., Canadian and German law‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- e3aa68e6875cabfdc776fde8bad7b45b7169ba653c0215e9e59be3036564fc4f
- Enrichment time
- 2026-04-09T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.