Russia Hacked Routers to Steal Microsoft Office Tokens

2026-04-09T01:23:32Ze3aa68e6875cabfdc776fde8bad7b45b7169ba653c0215e9e59be3036564fc4f
AI assistantsAisuruCanisterWormDDoSGandCrabIoT botnetIranJackSkidKimwolfMFA bypassMicrosoft OfficeMicrosoft Patch TuesdayMossadREvilRussiaStarkillerStrykerauthentication tokensdoxingnation-statepatch-managementphishing-as-a-serviceransomwarerouter vulnerabilitieswiper

What happened

Multiple high-impact cyber incidents and trends: Russian military-linked actors exploited known flaws in legacy routers to mass-harvest Microsoft Office authentication tokens from over 18,000 networks without installing malware; German authorities identified “UNKN” as Daniil Shchukin, linking him to REvil and GandCrab ransomware campaigns; an extortion group unleashed the CanisterWorm wiper that spreads via misconfigured cloud services and targets systems using Iran time zone or Farsi; Iran-linked actors claimed a wiper attack against medical device firm Stryker; U.S., Canadian and German law‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
e3aa68e6875cabfdc776fde8bad7b45b7169ba653c0215e9e59be3036564fc4f
Enrichment time
2026-04-09T01:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.