Microsoft Threat Intelligence Podcast

Russia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred Theft


Listen Later

This week on the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo speaks with Danny Adamitis, Distinguished Engineer at Lumen Technologies’ Black Lotus Labs who break down how the Russian state-linked threat actor Forest Blizzard is exploiting home and small office routers to hijack DNS traffic, enabling large-scale surveillance and targeted credential theft. The conversation highlights how this low-cost approach scales globally, why unmanaged routers have become a critical weak point, and how tactics, from brute force to token theft to DNS hijacking continue to evolve. 


In this episode you’ll learn:      

  • How Forest Blizzard exploits home routers to intercept DNS traffic 

    • Why unmanaged routers are a major blind spot in modern security 

      • How tactics have evolved from brute force to token-based access 

        Some questions we ask:     

        • What defines Forest Blizzard and how they operate? 

          • How does this impact machine-to-machine or service account security? 

            • What are the broader third-party or downstream risks? 


              Resources:  

              • View Danny Adamitis on LinkedIn  

                • View Sherrod DeGrippo on LinkedIn  

                  • Justice Department Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Intelligence Unit 

                    • FrostArmada: All thriller, no (malware) filler 

                       

                      Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                       

                      Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                       

                      The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      Microsoft Threat Intelligence PodcastBy Microsoft

                      • 5
                      • 5
                      • 5
                      • 5
                      • 5

                      5

                      22 ratings


                      More shows like Microsoft Threat Intelligence Podcast

                      View all
                      Hacked by Hacked

                      Hacked

                      187 Listeners

                      Security Now (Audio) by TWiT

                      Security Now (Audio)

                      2,011 Listeners

                      The Talk Show With John Gruber by Daring Fireball / John Gruber

                      The Talk Show With John Gruber

                      3,144 Listeners

                      Risky Business by Risky Business Media

                      Risky Business

                      371 Listeners

                      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                      651 Listeners

                      CyberWire Daily by N2K Networks

                      CyberWire Daily

                      1,028 Listeners

                      Smashing Security by Graham Cluley

                      Smashing Security

                      317 Listeners

                      Click Here by Recorded Future News

                      Click Here

                      418 Listeners

                      Darknet Diaries by Jack Rhysider

                      Darknet Diaries

                      8,077 Listeners

                      Cybersecurity Today by Jim Love

                      Cybersecurity Today

                      175 Listeners

                      Hacking Humans by N2K Networks

                      Hacking Humans

                      315 Listeners

                      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                      CISO Series Podcast

                      195 Listeners

                      Cybersecurity Headlines by CISO Series

                      Cybersecurity Headlines

                      139 Listeners

                      Cyber Hack by BBC World Service

                      Cyber Hack

                      1,600 Listeners

                      Risky Bulletin by Risky Business Media

                      Risky Bulletin

                      45 Listeners