The STRONTIUM APT group has been active since at least 2007 and it has targeted governments, militaries, and security organizations worldwide. Microsoft observed the group abusing IoT devices to gain access to several corporate networks. The group was involved also in the string of attacks that targeted 2016 Presidential election. Microsoft confirmed that in the last year it has delivered nearly 1400 nation-state notifications to entities that have been targeted or compromised by the Russia-linked APT. The attackers exploited default settings of the IoT devices (unchanged default password) in a third case the hacked device was not running an updated software.”]
Source: https://securityaffairs.co/wordpress/89473/apt/strontium-abuses-iot-devices.html

