Russia Hacked Routers to Steal Microsoft Office Tokens (krebsonsecurity.com)
- SOHO routers used as command-and-control pivot points.
- MFA bypass via session cookie exfiltration.
- Targeting of enterprise and governmental accounts.
"Russian-linked cyber actors are systematically compromising SOHO (Small Office/Home Office) routers to intercept Microsoft 365 authentication tokens. By positioning themselves as man-in-the-middle attackers through compromised edge devices, they steal active session cookies. This technique effectively renders Multi-Factor Authentication (MFA) useless, as the platform perceives the session as already verified. These attacks represent a significant escalation in threats to remote work resilience and organizational integrity, highlighting critical vulnerabilities in the hardware layer that supports European digital operations and public administration connectivity."
no comments yet.