惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
月光博客
月光博客
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
O
OpenAI News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Know Your Adversary
Know Your Adversary
Last Week in AI
Last Week in AI
S
Securelist
Engineering at Meta
Engineering at Meta
博客园 - 司徒正美
P
Privacy & Cybersecurity Law Blog
T
Tailwind CSS Blog
F
Fortinet All Blogs
博客园 - 三生石上(FineUI控件)
Scott Helme
Scott Helme
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
C
Cisco Blogs
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
小众软件
小众软件
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Hacker News: Ask HN
Hacker News: Ask HN
Hugging Face - Blog
Hugging Face - Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
SecWiki News
SecWiki News
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
Lohrmann on Cybersecurity
IT之家
IT之家
Security Archives - TechRepublic
Security Archives - TechRepublic
I
InfoQ
S
Security @ Cisco Blogs
Webroot Blog
Webroot Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
F
Full Disclosure
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The GitHub Blog
The GitHub Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
Cyberwarzone
Cyberwarzone
人人都是产品经理
人人都是产品经理
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research

Truesec

Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical Russia Rolls Out Surveillance Through State-Backed “Super App” MAX Device Code Phishing via Fake File-Sharing Invitation Active Exploitation of PAN‑OS Authentication Portal RCE - Truesec Windows Client Security Baselines: When Assumptions Meet Incident Response Reality - Truesec Entra ID Password Protection: From “P@ssw0rd” to Protected GitHub Under Attack: How Small Exposures Snowball into Large‑Scale Compromises European Risks Linked to the U.S. – Iran Conflict Mythos: What It Actually Means and What It Does Not Russian Espionage Campaign Targets Home Routers How Nordic Organizations Must Adjust Their Cybersecurity to a Changing Operating Environment Critical Vulnerability in “Ninja Forms – File Upload” WordPress Plugin (CVE-2026-07409) Iranian APT Target US Critical Infrastructure Remote Access – Is VPN the Almighty Solution? Malicious Axios Packages Published to npm in New Supply Chain Compromise RCE Vulnerability in F5 BIG-IP APM (CVE-2025-53521) No Further Increase in Iranian Cyber Operations Malicious PyPI Package – LiteLLM Supply Chain Compromise Dutch Intelligence Warns of Russian Campaign Against Signal and Whatsapp Users Multiple Vulnerabilities, One Critical, in Ubiquiti UniFi Network Application
Russian Intelligence Targets SOHO Routers - Truesec
Hjalmar Desmond · 2026-07-16 · via Truesec

Threat Insight

The Russian GRU threat actor known as Forest Blizzard, has conducted a large-scale cyber espionage campaign by targeting small office and home office (SOHO) routers, to conduct adversary-in-the-middle (AitM) attacks.

The threat actor targeted unprotected routers and manipulates their DNS settings so that traffic to certain domains gets redirected to an AitM site, where victims are lured to enter their credentials into a fake login page that stores the credentials and then redirects them to the real site, using the same credentials.

This campaign uses a well-known technique to harvest credentials and session tokens via an AitM site. The novel part is that instead of using phishing links to lure the victim to visit the fraudulent site, they manipulate DNS records to direct them to the AitM site. This type of attack can be especially powerful against people working from home, with a private home router.

This is not the first time sophisticated threat actors have focused on routers in their cyber espionage campaigns. Truesec has previously reported how both Russian and Chinese threat actors have targeted routers.

Recommended Actions

What This Means

This is a network architecture issue in the remote work model. If remote access depends on unmanaged or weakly managed edge devices, attackers gain a path into identity flows and business traffic without touching the endpoint first. Leadership should view this as a risk in the digital workplace architecture and in the trust model for remote work.

MITRE ATT&CK Connection

ATT&CK pattern: This attack stands out through adversary-in-the-middle activity from compromised routers. The attacker intercepts traffic, captures credentials or sessions, and abuses normal authentication flows without needing to compromise the endpoint first.

Architectural weak point: The remote work model often trusts home routers and other edge devices that the organization does not manage well enough. That means identity and network trust depend on infrastructure outside normal enterprise control.

NIST CSF

Identify: Asset Management (ID.AM): Know which routers, edge devices, DNS paths, and home office setups influence access to critical services.

Protect: Platform Security (PR.PS): Harden remote access paths, edge devices, and supporting network services.
Identity Management, Authentication, and Access Control (PR.AA): Reduce trust in unmanaged networks through stronger access controls such as VPN and MFA.

Detect: Continuous Monitoring (DE.CM) and Adverse Event Analysis (DE.AE): Look for unusual authentication patterns and signs of traffic interception.

Respond: Incident Management (RS.MA): Contain affected users, devices, and network paths fast.

Recover: Incident Recovery Plan Execution (RC.RP): Restore trusted access after the affected paths are contained.

What To Do

  • Treat routers and network edge devices as part of the enterprise attack surface.
  • Set clear architectural rules for home offices, remote access, DNS control, device hardening, and support responsibilities.
  • Reduce dependence on unmanaged home networking for access to sensitive services.
  • Use stronger controls such as VPN, MFA, centralized DNS, traffic filtering, secure web access, and managed connectivity where risk is high.
  • Review how you update, monitor, and replace routers and other network or IoT devices used in remote work settings.
  • Ensure policies cover both corporate devices and personal devices that influence business traffic.

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights