Details have emerged about a sophisticated cyberespionage campaign dubbed FrostArmada, attributed to the Russian state-sponsored threat group Forest Blizzard (more widely known as APT28 or Fancy Bear). The campaign involved compromising network gateway routers, especially in hospitality environments like hotels and conference centers, to conduct DNS poisoning attacks. By modifying the DNS settings on these routers, the attackers established a Man-in-the-Middle (MitM) position, allowing them to intercept web traffic from users on the Wi-Fi network. This position was leveraged to harvest Microsoft credentials and OAuth tokens as users attempted to log into legitimate services, providing the attackers with access to a wide array of corporate accounts.
Threat Actor: Forest Blizzard (APT28) is a highly skilled Russian General Staff Main Intelligence Directorate (GRU) threat group known for targeting governments, military, and security organizations for intelligence gathering. Their TTPs are often stealthy and sophisticated.
Attack Vector: The core of the FrostArmada campaign is the compromise of edge network devices (T1189 - Drive-by Compromise) and subsequent DNS manipulation. By targeting routers in public or semi-public locations, the attackers can efficiently target a diverse and high-value set of victims with a single infrastructure compromise. This is a highly effective technique for credential harvesting at scale.
The attack chain for the FrostArmada campaign is as follows:
T1547.001 - Registry Run Keys / Startup Folder): Once on the router, the attackers modify its DNS configuration. They change the DNS server settings to point all DNS queries from connected clients to an attacker-controlled DNS server.T1557 - Man-in-the-Middle): When a user on the compromised Wi-Fi network attempts to browse to a site like login.microsoftonline.com, their DNS query is sent to the malicious server. The server responds with the IP address of an attacker-controlled phishing server instead of the legitimate Microsoft IP.T1566.002 - Spearphishing Link): The user's browser is directed to the phishing server, which presents a pixel-perfect clone of the Microsoft login page. The unsuspecting user enters their credentials and potentially an MFA token, which are captured by the attackers.The campaign was reportedly disrupted in April 2026 through a joint operation.
This campaign poses a significant threat, especially to business travelers and government employees:
No specific Indicators of Compromise were provided in the source articles.
For individuals and organizations, detecting this attack is challenging. However, some hints include:
Educate users on the risks of public Wi-Fi and the importance of using a VPN.
While not foolproof against MitM, phishing-resistant MFA like FIDO2 can prevent credential theft.
Using DNS over HTTPS (DoH) can prevent local network DNS poisoning attacks.
Mandating the use of a corporate VPN encrypts traffic and routes DNS queries through a trusted channel.
The FrostArmada campaign was reportedly disrupted by a joint operation.
Further details of the FrostArmada campaign are publicly reported.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.