Russia Hacked Routers to Steal Microsoft Office Tokens

2026-04-14T01:23:34Zefc297b3a7e05f0980ae8fadf3b1a0bef2a18253064b879c3465b207962fffca
anonymity-networkauthentication-tokenscanisterwormcloud-servicesddosespionagegandcrab','doxxing','vulnerability-management','patch-tuesday','i2piot-botnetiraniran-linkedkimwolfmfa-bypassmicrosoft-officenation-statephishingphishing-as-a-serviceransomwarerevilroutersrussiastarkillersupply-chaintoken-theftwiper

What happened

Multiple KrebsOnSecurity reports describe a wave of high-impact cyber activity: Russian military-intel-linked actors exploited known flaws in older consumer and enterprise routers to mass-harvest Microsoft Office authentication tokens from users on over 18,000 networks without deploying malware; separate reporting covers doxxing of a suspected REvil/GandCrab leader (UNKN/Daniil Shchukin), a worm-like wiper (“CanisterWorm”) targeting Iran, and an Iran-linked wiper claim against medtech firm Stryker. U.S., Canadian and German authorities disrupted four large IoT botnets (Aisuru, Kimwolf, JackSk2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
efc297b3a7e05f0980ae8fadf3b1a0bef2a18253064b879c3465b207962fffca
Enrichment time
2026-04-14T01:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.