Russia Hacked Routers to Steal Microsoft Office Tokens
2026-04-14T01:23:34Z•efc297b3a7e05f0980ae8fadf3b1a0bef2a18253064b879c3465b207962fffca
anonymity-networkauthentication-tokenscanisterwormcloud-servicesddosespionagegandcrab','doxxing','vulnerability-management','patch-tuesday','i2piot-botnetiraniran-linkedkimwolfmfa-bypassmicrosoft-officenation-statephishingphishing-as-a-serviceransomwarerevilroutersrussiastarkillersupply-chaintoken-theftwiper
What happened
Multiple KrebsOnSecurity reports describe a wave of high-impact cyber activity: Russian military-intel-linked actors exploited known flaws in older consumer and enterprise routers to mass-harvest Microsoft Office authentication tokens from users on over 18,000 networks without deploying malware; separate reporting covers doxxing of a suspected REvil/GandCrab leader (UNKN/Daniil Shchukin), a worm-like wiper (“CanisterWorm”) targeting Iran, and an Iran-linked wiper claim against medtech firm Stryker. U.S., Canadian and German authorities disrupted four large IoT botnets (Aisuru, Kimwolf, JackSk2
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- efc297b3a7e05f0980ae8fadf3b1a0bef2a18253064b879c3465b207962fffca
- Enrichment time
- 2026-04-14T01:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.