Russia Hacked Routers to Steal Microsoft Office Tokens

2026-04-08T01:23:30Ze6202aaf83af5b1070733655efd9b0526ebfef8d5129c60b920d71e899b0e04f
AisuruCanisterWormDDoSDaniil ShchukinGandCrabI2P disruptionIoT botnet disruptionIran targetingJackSkidKimwolfMFA relayMicrosoft Office token theftMicrosoft Patch Tuesday March 2026 (77 fixes)MossadREvilRussiaStarkiller phishing-as-a-serviceStryker wiper claimcloud-service wormcredential/token harvestingdoxingmilitary intelligencephishingrouter exploitationwiper

What happened

Multiple high-impact cyber incidents and trends reported by KrebsOnSecurity: Russian military-intelligence–linked actors exploited known vulnerabilities in older home/edge routers to mass-harvest Microsoft Office authentication tokens from users on over 18,000 networks without deploying malware; German authorities identified and doxxed Daniil Maksimovich Shchukin ("UNKN"), alleged leader of GandCrab and REvil ransomware groups; a financially motivated group deployed the "CanisterWorm" wiper that spreads via poorly secured cloud services and targets systems using Iran time zone/Farsi locale; US

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
e6202aaf83af5b1070733655efd9b0526ebfef8d5129c60b920d71e899b0e04f
Enrichment time
2026-04-08T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.