FrostArmada: The APT28 DNS Hijacking Campaign That Hit 18,000 Devices Across 120 Countries
AEGIDA THREAT BRIEFING — April 17, 2026 — TLP:WHITE
Classification: TLP:WHITE — Unlimited distribution. This document may be shared freely. Primary sources: Black Lotus Labs / Lumen Technologies analysis, Microsoft Threat Intelligence advisory, FBI/DOJ press releases, CERT-PL telemetry. Analysis and correlation: AEGIDA Research Team.
KEY JUDGMENTS
- KJ-1: APT28 (Forest Blizzard / Storm-2754 / Fancy Bear), GRU unit 26165, conducted a systematic DNS hijacking campaign on consumer and SMB routers between May 2025 and April 2026, designated FrostArmada by Black Lotus Labs, peaking at 18,000 compromised devices across 120 countries in December 2025. (HIGH CONFIDENCE)
- KJ-2: The primary objective was mass harvesting of Microsoft 365 credentials and OAuth tokens through Adversary-in-the-Middle (AitM) proxies, with specific targeting of government agencies, law enforcement, IT/hosting companies, and at least one European national digital identity platform. (HIGH CONFIDENCE)
- KJ-3: The campaign operated with two functionally separate teams — an "expansion team" for botnet growth and an "AitM team" for credential harvesting — suggesting operational maturity and internal compartmentation consistent with high-tier GRU operations. (MODERATE CONFIDENCE)
- KJ-4: The disruption operation on April 7, 2026 — conducted by FBI, DOJ, the Polish government, Microsoft, and Lumen — neutralized the command-and-control infrastructure but does not eliminate residual risk on devices whose DNS settings have not been restored or whose firmware remains vulnerable. (HIGH CONFIDENCE)
ASSESSMENT 1 — Anatomy of the FrostArmada Campaign
1.1 Actor and Operational Context
APT28 is the Western designator for unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). Active since at least 2004, the unit is responsible for some of the most consequential cyber operations of the past two decades: from the compromise of the German Bundestag in 2015, to interference in the 2016 U.S. presidential elections, to the PRISMEX campaign against NATO and Ukrainian infrastructure documented by AEGIDA on April 10, 2026. The group operates under multiple designators depending on the threat intelligence vendor: Fancy Bear (CrowdStrike), Forest Blizzard and Storm-2754 (Microsoft), Sofacy (Kaspersky), Pawn Storm (Trend Micro), Sednit (ESET).
FrostArmada represents a significant tactical evolution from traditional APT28 operations. Historically, the group has favored spear-phishing, exploitation of vulnerabilities in internet-facing services, and email relay abuse. With FrostArmada, APT28 adopted an infrastructural approach: rather than targeting end victims directly, it compromised intermediate network infrastructure — routers — to position itself as an invisible intermediary in the DNS traffic of thousands of organizations simultaneously. It is the difference between fishing with a hook and fishing with a trawl net.
1.2 Operational Timeline
- 1.May 2025 — First documented compromises of MikroTik and TP-Link routers. The expansion team begins building the botnet by exploiting default credentials, outdated firmware, and known unpatched vulnerabilities.
- 2.June-September 2025 — Steady botnet expansion. Compromised devices are configured to modify DNS parameters distributed via DHCP to local network clients, redirecting DNS traffic to attacker-controlled servers.
- 3.October 2025 — Nethesis routers (prevalent in Italy) and older Fortinet devices with outdated firmware are integrated into the botnet. The AitM team begins limited-scale credential harvesting operations, likely in a testing phase.
- 4.December 2025 — Campaign peak: 18,000 compromised devices across 120 countries. The AitM team operates at full capacity. Microsoft identifies 200+ organizations and 5,000+ consumer devices impacted by credential harvesting.
- 5.January-March 2026 — The campaign continues at stable intensity. Black Lotus Labs publishes its first internal technical analysis and coordinates with authorities.
- 6.April 7, 2026 — Joint disruption operation. The FBI obtains court authorization to remotely reset malicious DNS configurations on reachable compromised routers. The DOJ publicly announces the takedown. The Polish government and Microsoft contribute complementary resources.
1.3 Attack Chain — From Router Compromise to Credential Theft
The FrostArmada attack chain unfolds in four distinct phases, each managed with increasing levels of automation.
Phase 1 — Router compromise. The expansion team identifies internet-exposed routers with accessible management interfaces (Winbox for MikroTik, web interfaces for TP-Link and Nethesis, management consoles for Fortinet). Access is gained through unchanged default credentials, exploitation of known vulnerabilities on outdated firmware, or brute-force attacks on weak passwords. Once inside, the team modifies two critical parameters: the primary and secondary DNS servers assigned to clients via DHCP, and in some cases firewall rules to ensure persistence.
Phase 2 — Silent DNS hijacking. From this point, every device connected to the compromised router's local network — PCs, smartphones, tablets, internal servers — receives a malicious DNS server via DHCP instead of the legitimate one. The malicious DNS server responds correctly to the vast majority of queries (forwarding them to legitimate upstream resolvers) but selectively intercepts requests for specific domains: login.microsoftonline.com, outlook.office365.com, login.windows.net, and other Microsoft 365 authentication endpoints. For these domains, the malicious DNS returns the IP address of an attacker-controlled AitM proxy.
Phase 3 — Adversary-in-the-Middle proxy. The AitM proxy terminates the user's TLS connection and opens a new one toward the legitimate Microsoft server, acting as a transparent relay. The user sees the authentic Microsoft 365 login page, enters their credentials, completes any multi-factor authentication (MFA), and receives their session token. The proxy intercepts and records everything: username, password, OAuth token, session cookies. The only visible signal for the user is a browser TLS certificate warning: the certificate presented by the proxy is not Microsoft's, is not signed by a recognized certificate authority, and the browser flags it. Ignoring that warning — as millions of users do daily — is equivalent to surrendering one's credentials.
Phase 4 — Credential exploitation. OAuth tokens and credentials harvested by the AitM team are used to access victims' email inboxes, SharePoint documents, and Teams conversations. In at least one case documented by Microsoft, stolen credentials were used to access a European national digital identity platform, suggesting the target was not just email access but the organization's entire digital identity chain.
The critical point in the entire chain is the TLS certificate warning. Every modern browser displays it. But years of false alarms, internal portals with self-signed certificates, and ingrained habits have taught users to click "Proceed anyway." In this campaign, that click was the only action required from the end victim. Everything else — from router compromise to DNS hijacking — occurred without any end-user interaction.
ASSESSMENT 2 — Infrastructure and Technical Indicators
2.1 Operational Compartmentation
FrostArmada's operational architecture reveals a level of internal compartmentation unusual even by APT28 standards. Black Lotus Labs identified two functionally separate activity clusters with distinct infrastructure and minimal overlap.
The expansion team managed botnet growth: mass scanning, compromise attempts, router persistence, DNS parameter updates. It operated at broad scale with high automation, prioritizing volume over targeting. Its objective was to maximize the number of local networks under DNS control, regardless of the specific value of connected targets.
The AitM team managed the proxy infrastructure and credential collection. It operated more selectively: not all domains were hijacked, not all botnet routers were configured to redirect to AitM proxies simultaneously. This suggests a "collect-then-filter" operation — harvesting credentials at scale and subsequently selecting those of intelligence interest.
2.2 Identified VPS Infrastructure
Analysis by Black Lotus Labs and information released through the disruption operation identified six VPS servers used as command-and-control nodes and AitM proxies. These addresses should be considered high-confidence indicators of compromise.
- 64.120.31.96 — Command-and-control server (expansion team).
- 79.141.160.78 — Primary AitM proxy node, active since October 2025.
- 23.106.120.119 — Payload management and distribution VPS for MikroTik routers.
- 79.141.173.211 — Secondary AitM proxy node, activated in December 2025 to handle traffic surge.
- 185.117.89.32 — Malicious DNS server, configured as primary resolver on compromised routers.
- 185.237.166.55 — Secondary malicious DNS server, used as fallback.
Immediate action: check perimeter firewall logs and DNS query logs for connections to the six IPs listed above. Also verify that no network device has statically configured these addresses as DNS servers. Even after disruption, devices that cached these DNS entries in static configurations will continue attempting connections to them.
ASSESSMENT 3 — The Disruption Operation of April 7, 2026
On April 7, 2026, the U.S. Department of Justice publicly announced the dismantling of FrostArmada infrastructure through a joint operation involving the FBI, DOJ, Polish government, Microsoft Threat Intelligence, and Lumen Technologies / Black Lotus Labs.
The operation was conducted under court authorization: a U.S. federal court authorized the FBI to remotely interact with compromised routers to reset malicious DNS configurations to default values. This type of operation — where a government agency modifies the configuration of private devices without explicit owner consent but with judicial authorization — follows the precedent set by operations against the Emotet (2021) and Cyclops Blink (2022) botnets. The legality and appropriateness of this approach remain debated in the security community, but the alternative — individually notifying the owners of 18,000 routers across 120 countries and hoping they act — is operationally impractical when the infrastructure is actively used for hostile intelligence operations.
Poland's role is particularly relevant: Poland was among the most heavily impacted countries, consistent with APT28's targeting of NATO eastern flank nations. CERT-PL provided critical telemetry and coordinated with local providers to identify compromised devices on Polish territory.
3.1 Limitations of the Disruption
It is important to understand what the disruption accomplished and what it did not. It neutralized the six identified VPS servers, reset DNS configurations on a portion of reachable routers, and interrupted the active credential harvesting chain. It did not patch vulnerable firmware. It did not change weak passwords on routers. It did not eliminate backdoors potentially installed by the expansion team beyond the DNS modification. It did not revoke already-stolen OAuth tokens that may still be valid.
In other words: the disruption cut the strings between puppet and puppeteer, but it did not repair the puppet. Routers that were vulnerable before the disruption remain vulnerable after. The attackers — or other actors with the same exploit arsenal — can re-compromise the same devices. The only lasting protection is firmware updates, credential changes, and configuration hardening by the device owner.
ASSESSMENT 4 — Correlation with the PRISMEX Campaign
On April 10, 2026, AEGIDA published a detailed analysis of the PRISMEX campaign, another APT28 operation active during the same period and focused on NATO infrastructure and Ukrainian targets. The temporal overlap between FrostArmada and PRISMEX is not coincidental: the GRU historically operates multiple campaigns in parallel, with dedicated teams and compartmented infrastructure but convergent strategic objectives.
FrostArmada and PRISMEX share the actor but differ radically in tactics. PRISMEX is a surgical operation, directed at specific high-value targets, with personalized spear-phishing and custom payloads. FrostArmada is a trawling operation that sacrifices targeting precision for collection scale. Together, the two campaigns compose an operational picture in which APT28 attacks simultaneously in depth (PRISMEX) and breadth (FrostArmada), maximizing both the quality and quantity of collected intelligence.
The coexistence of PRISMEX and FrostArmada suggests that APT28/GRU 26165 currently operates with sufficient operational resources to sustain at least two significant-scale campaigns in parallel. This is consistent with Western intelligence community assessments of growing Russian offensive cyber capabilities in the post-2022 period.
OUTLOOK
With moderate confidence, we assess the following developments as probable within 90 days of the disruption.
- APT28 will rebuild the botnet infrastructure within 60-90 days, using the same vector (routers with vulnerable firmware and weak credentials) or adapting to new targets (routers from other vendors, IoT devices with DNS capabilities). The barrier to reconstruction is low because the pool of vulnerable devices was not reduced by the disruption.
- OAuth tokens stolen before the disruption remain potentially valid and usable for persistent access to already-compromised organizations. Organizations identified by Microsoft should have received notifications, but complete token revocation and anomalous access verification takes weeks.
- The DNS hijacking via compromised router technique will be adopted by other state and criminal actors. FrostArmada's operational model is relatively simple to replicate and the attack surface is global. It is plausible that variants of the same technique will emerge by end of 2026, attributed to different actors.
- Security apparatus attention to home and SMB routers as a compromise vector will increase, but the patching speed of the network device ecosystem remains structurally slow. The gap between risk awareness and effective mitigation will close gradually.
INDICATORS OF COMPROMISE
The following indicators are classified by type and confidence level. Immediate ingestion into SIEM, EDR, and perimeter firewall systems is recommended.
IP Addresses — C2 and AitM Proxies (High Confidence)
- 64.120.31.96 — C2 server (expansion team)
- 79.141.160.78 — Primary AitM proxy
- 23.106.120.119 — MikroTik payload distribution
- 79.141.173.211 — Secondary AitM proxy
- 185.117.89.32 — Primary malicious DNS
- 185.237.166.55 — Secondary malicious DNS
Behavioral Indicators (Moderate Confidence)
- Unauthorized modification of DNS parameters in the router's DHCP server.
- DNS queries to the six listed IPs from internal network devices.
- TLS warnings for invalid certificates on Microsoft 365 domains (login.microsoftonline.com, outlook.office365.com, login.windows.net).
- Microsoft 365 logins from IPs not correlated to the user's usual geolocation, especially if immediately following TLS warnings.
- Outbound connections from the router management port (8291/tcp for MikroTik Winbox, 443/tcp for web interfaces) to unknown IPs.
- Presence of firewall rules on the router blocking access to the vendor's firmware update servers.
RECOMMENDED ACTIONS
The following actions are ordered by priority and applicability. Actions 1-4 are considered urgent and should be completed within 72 hours of this briefing's publication.
- 1.Immediate DNS verification: access the management interface of every MikroTik, TP-Link, Nethesis, and Fortinet router on the network. Verify that DNS servers configured in the DHCP server match the organization's or provider's legitimate DNS. Compare against the six malicious IPs listed above. If DNS settings have been modified, consider the device compromised and proceed to action 2.
- 2.Compromised router restoration and hardening: perform a factory reset. Update firmware to the latest stable version. Reconfigure from scratch with strong credentials (minimum 16 characters, unique per device). Disable management interfaces on WAN ports. Restrict management access to specific IPs via ACLs.
- 3.Microsoft 365 credential revocation: for all users accessing Microsoft 365 through networks served by potentially compromised routers, force password reset and revoke all active OAuth tokens via the Azure AD portal. Enable Sign-In Risk Policy if not already active.
- 4.IoC ingestion into monitoring systems: load the six IPs into perimeter firewall blocklists, SIEM rules, and EDR feeds. Configure alerts for connections to these IPs, even after disruption, as indicators of devices not yet remediated.
- 5.Firmware management policy: implement a firmware verification and update cycle for network devices on at least a quarterly basis. Document firmware versions in a centralized inventory. Routers are not "set and forget" — they are the weakest link in the security chain when treated as such.
- 6.User training on TLS warnings: educate staff on the meaning of browser certificate warnings. The rule is simple: if the browser flags an invalid certificate on a login site — Microsoft, Google, any corporate service — do not proceed. Report to IT. This is the only user-side defense against this type of AitM attack.
- 7.DNS segmentation and monitoring: configure clients to use DNS over HTTPS (DoH) or DNS over TLS (DoT) toward trusted resolvers, bypassing router-provided DNS. Monitor DNS queries at the network level to identify anomalous resolutions to unexpected IPs for Microsoft domains.
Methodological Note and Sources
This threat briefing is based on the following primary sources: Black Lotus Labs / Lumen Technologies, technical report "FrostArmada: APT28 DNS Hijacking Campaign" (April 2026); Microsoft Threat Intelligence, advisory "Forest Blizzard DNS hijacking via compromised routers" (April 2026); FBI / DOJ, press release and judicial affidavit on the disruption operation (April 7, 2026); CERT-PL, technical advisory for Polish providers (April 2026); AEGIDA Research Team, correlation with PRISMEX analysis of April 10, 2026. Confidence levels: HIGH = multiple concordant and verifiable sources; MODERATE = limited but consistent sources with known patterns; LOW = plausible analytical inference, unconfirmed.