APT28 steals your Microsoft tokens without touching your Mac
Russian military intelligence is exploiting unpatched routers to silently intercept your Office OAuth tokens. What you need to do.
APT28, the military intelligence arm of Russia’s GRU, has compromised over 18,000 consumer routers to intercept Microsoft Office authentication tokens. No malware on endpoints. No antivirus alerts. Just your router lying to you.
What’s happening
APT28, Advanced Persistent Threat 28, is the group behind, among other things, the 2016 hack of the Democratic National Committee. They operate under the “Forest Blizzard” moniker on Microsoft’s side and work for Russia’s Main Directorate of Intelligence (GRU).
Their latest operation, revealed on April 7, 2026, by Krebs on Security, Black Lotus Labs (Lumen), and the UK’s NCSC, is eerily simple.
The method: exploit known vulnerabilities on unpatched Mikrotik and TP-Link routers to modify their DNS settings. Once compromised, the router silently becomes a malicious intermediary, rerouting all network DNS requests through servers controlled by APT28.
The goal: intercept OAuth Microsoft Office tokens. These tokens are sent after user authentication, including two-factor (MFA). APT28 gets direct access to Microsoft accounts without ever phishing a password.
At the peak of the operation in December 2025, 18,000 networks were ensnared. Microsoft identified over 200 organizations and 5,000 compromised devices. Priority targets: government agencies, foreign ministries, third-party email providers.
Fun fact on the timeline: APT28 previously used targeted malware on a small number of routers. After the NCSC’s first report in August 2025, they switched to mass DNS poisoning overnight. When GRU hackers adapt in 24 hours to a public report, it’s a sign of their level.
Why it matters to you
Your Mac’s chain of attack remains untouched. No suspicious processes, no unknown files, no Gatekeeper alerts. Your antivirus can take a nap; it’s not involved.
What’s compromised is the layer below: your local network’s DNS infrastructure. Your Mac trusts its network, and the network lies.
The attack technically requires you to ignore an invalid TLS certificate alert in your browser or email client. It’s not trivial, but most people click “Continue anyway” without reading, and APT28 knows it.
APT28 historically targets governments, journalists, and NGOs. But 18,000 consumer routers in the mix means they’re casting a wide net. If you’re using Microsoft Office on a network with an outdated router, you might be in the net.
Read soon: Why DNS is the Achilles heel of your privacy
What you need to do
1. Update your router’s firmware, right now
Connect to your router’s admin interface (usually 192.168.1.1 or 192.168.0.1), find the “Update” or “Firmware update” section, and apply. If your router no longer receives updates (end of life), it’s time for a replacement.
2. Configure Quad9 directly on your Mac, not on the router
This is key. If you leave your Mac using the router’s DNS, and the router is compromised, it’s game over. By configuring a DNS server directly on your Mac, you bypass the router.
System Preferences > Network > select your Wi-Fi or Ethernet connection > Details > DNS > remove existing servers > add 9.9.9.9 (Quad9, Switzerland, privacy-first).
To verify, open Terminal and type:
scutil --dns | grep nameserver
You should see 9.9.9.9. If you see an IP like 192.168.x.x, it’s still the router responding.
3. Enable DNS-over-HTTPS if possible
Quad9 supports DNS-over-HTTPS (DoH), which encrypts your DNS queries and makes them unreadable even to a network intermediary. On macOS 14+, you can enable DoH via a configuration profile or a client like dnscrypt-proxy. It’s a bit more involved, but if you’re hosting a local DNS resolver on your network, it’s the next natural step.
4. Never ignore a TLS certificate alert
If your browser or email client shows an invalid certificate error on a service you usually use without issue, don’t click “Continue”. Close, check your connection, and if the problem persists, it’s a strong sign something’s not right on your network.