FrostArmada is a campaign name associated with router-focused credential and token theft activity that has been assessed as overlapping with tradecraft linked to APT28, also known as Fancy Bear, Forest Blizzard, Sednit, Sofacy, Pawn Storm, STRONTIUM, BlueDelta, and UAC-0001. The activity is characterized by compromise of internet-facing network edge devices, especially SOHO routers and captive-portal Wi-Fi gateways, followed by manipulation of DNS settings or DNS responses to redirect victims to Microsoft-impersonation infrastructure. The objective is to compromise Microsoft 365 accounts belonging to traveling corporate users and other victims connecting through affected networks. Observed tradecraft includes gaining administrative access to exposed management interfaces on gateway devices, likely aided by weak or reused administrative credentials; altering DNS behavior to poison or forge responses; redirecting users to spoofed Microsoft authentication pages for credential theft; and, in some cases, abusing Microsoft device-code authentication flows to obtain MFA-satisfied OAuth tokens without directly stealing passwords. Additional activity has included attempted WPAD abuse to coerce systems into using attacker-controlled proxy settings, potentially expanding interception beyond authentication traffic. Reporting has noted operator infrastructure consistent with account-compromise operations and content management for phishing or authentication-lure pages. FrostArmada has been discussed in connection with an April 2026 campaign targeting SOHO routers, while later related activity used similar techniques against hospitality and conference Wi-Fi gateways. Attribution to APT28 has been assessed only with low-to-moderate confidence based on TTP overlap rather than direct technical linkage such as shared infrastructure or malware reuse. The dominant pattern is credential and session compromise in support of espionage-oriented access against enterprise users across multiple sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign/activity cluster referenced as exhibiting similar gateway targeting and DNS poisoning tradecraft; previously reported targeting home routers and used here as the closest comparison for the observed hotel Wi-Fi campaign.
A prior campaign used as the main comparison point for the current activity; it compromised SOHO routers, altered DNS settings, redirected traffic to attacker-controlled servers, and enabled theft of Microsoft logins and OAuth tokens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.