Russian intelligence-linked operations are increasingly focused on communications-layer collection, using compromised SOHO routers, DNS hijacking, and phishing against Signal, WhatsApp, Telegram, and Microsoft 365. These campaigns are attributed largely to the Russian GRUâs Unit 26165 (APT28/Fancy Bear/Forest Blizzard) and target government, defense, critical infrastructure, journalists, NGOs, and Ukraine-related organizations for persistent access and intelligence gathering. #APT28 #FancyBear #ForestBlizzard #Unit26165 #Signal #WhatsApp #Telegram #Microsoft365
Keypoints
- Russian operators are prioritizing quiet, long-term intelligence collection over destructive activity.
- Compromised SOHO routers are being used for DNS hijacking, adversary-in-the-middle collection, and credential interception.
- The router activity is attributed to the Russian GRUâs Unit 26165, tracked as APT28, Fancy Bear, and Forest Blizzard.
- Messaging-platform targeting extends to Signal, WhatsApp, Telegram, and Microsoft 365, including linked-device abuse and OAuth phishing.
- Victims of highest interest include government, military, defense, critical infrastructure, telecom, journalists, NGOs, researchers, and Ukraine-linked groups.
- Microsoft, FBI, CISA, DOJ, Google, Volexity, and other reporting indicate broad-scale compromise with selective follow-on targeting.
- Defensive guidance emphasizes router hardening, linked-device review, phishing-resistant MFA, and tighter control of OAuth and remote access.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â Vulnerable SOHO and TP-Link routers were exploited to gain initial access [âExploitation of vulnerable SOHO and TP-Link routersâ]
- [T1566 ] Phishing â Messaging-app phishing and OAuth lure delivery were used to obtain access [âMessaging-app phishing and OAuth lure deliveryâ]
- [T1566.002 ] Spearphishing Link â Malicious OAuth and device-code URLs were delivered to victims [âDelivery of malicious OAuth/device-code URLsâ]
- [T1078 ] Valid Accounts â Compromised messaging and cloud accounts were abused for continued access [âAbuse of compromised messaging and cloud accountsâ]
- [T1204 ] User Execution â Victims interacted with QR codes and phishing links to enable compromise [âVictim interaction with QR codes and phishing linksâ]
- [T1098 ] Account Manipulation â Linked devices were added to Signal accounts for persistence [âAddition of linked devices to Signal accountsâ]
- [T1133 ] External Remote Services â Compromised cloud identities were used to maintain access [âContinued access through compromised cloud identitiesâ]
- [T1556 ] Modify Authentication Process â OAuth workflow abuse and session persistence were leveraged [âOAuth workflow abuse and session persistenceâ]
- [T1548 ] Abuse Elevation Control Mechanism â Router administrative compromise and configuration changes elevated control [âRouter administrative compromise and configuration manipulationâ]
- [T1090 ] Proxy â DNS and adversary-in-the-middle proxy routing was used to steer traffic [âDNS and AiTM proxy routingâ]
- [T1562 ] Impair Defenses â The actors operated outside enterprise EDR visibility [âOperating outside enterprise EDR visibilityâ]
- [T1557 ] Adversary-in-the-Middle â TLS interception and DNS redirection enabled interception of traffic [âTLS interception and DNS redirectionâ]
- [T1649 ] Steal or Forge Authentication Certificates â Fraudulent or invalid TLS certificates were used to enable interception [âUse of fraudulent/invalid TLS certificatesâ]
- [T1056 ] Input Capture â Credentials were intercepted via redirected authentication flows [âCredential interception via redirected authentication flowsâ]
- [T1555 ] Credentials from Password Stores â Stored or synced credentials were intercepted [âInterception of stored or synced credentialsâ]
- [T1046 ] Network Service Discovery â DNS visibility was used for reconnaissance [âReconnaissance through DNS visibilityâ]
- [T1016 ] System Network Configuration Discovery â Resolver and network settings were observed [âObservation of network and resolver configurationsâ]
- [T1589 ] Gather Victim Identity Information â Contact lists and identity relationships were collected [âCollection of contact lists and identity relationshipsâ]
- [T1590 ] Gather Victim Network Information â DNS and routing visibility were collected [âDNS and routing visibility collectionâ]
- [T1114 ] Email Collection â Outlook Web Access traffic was intercepted [âInterception of Outlook Web Access trafficâ]
- [T1123 ] Audio Capture â Communication workflows could support audio-related collection [âPotential collection through compromised communication workflowsâ]
- [T1213 ] Data from Information Repositories â Cloud-hosted communications were accessed [âAccess to cloud-hosted communicationsâ]
- [T1113 ] Screen Capture â Follow-on account monitoring activities could include screen capture [âPotential follow-on account monitoring activitiesâ]
- [T1530 ] Data from Cloud Storage â Microsoft 365 and cloud-message access enabled collection [âMicrosoft 365 and cloud-message accessâ]
- [T1071 ] Application Layer Protocol â DNS and HTTPS were used for communications [âDNS- and HTTPS-based communicationsâ]
- [T1573 ] Encrypted Channel â TLS/HTTPS transport protected communications [âUse of TLS/HTTPS transportâ]
- [T1568 ] Dynamic Resolution â Actor-controlled DNS infrastructure supported routing and redirection [âActor-controlled DNS infrastructureâ]
- [T1567 ] Exfiltration Over Web Service â Cloud-account data access and exfiltration occurred through web services [âCloud-account data access and exfiltrationâ]
- [T1498 ] Network Denial of Service â Router control may provide latent disruptive capability [âPotential latent capability through router controlâ]
- [T1574 ] Hijack Execution Flow â DNS response manipulation redirected traffic [âDNS response manipulation and traffic redirectionâ]
Indicators of Compromise
- [Threat actor aliases ] Russian GRU-linked cluster referenced in the report â APT28, Fancy Bear, Forest Blizzard, and Unit 26165
- [Organizations/services targeted ] Messaging and cloud platforms abused for collection â Signal, WhatsApp, Telegram, Microsoft 365, and Outlook Web Access
- [Device/vendor references ] Compromised edge devices mentioned in the campaign â TP-Link devices, SOHO routers
- [Time references ] Reported campaign duration and warning period â August 2025, April 2026, March 2026
- [Scale indicators ] Broad compromise described by researchers and agencies â more than 18,000 IPs, more than 200 organizations, 5,000 consumer devices