This is the reply from the braiins pool support team:
It's hard to say from here. It's possible that perhaps it is defaulting to an old setting.
My advice would be to make sure it has the latest firmware (a fresh install may be a good idea), make sure your local network is secure and change any passwords/log in for the user interface/firmware. You may want to consider using a VPN also.
I don't have much expertise but until someone more knowledgeable chimes in, here's my 2 Sats worth:
How did you work out where your hashes are being forwarded to? "username : portforwarded.futurebit" sounds like it might be a default setting rather than man in the middle. Maybe your SD card image is old, mine had a different username in it before I changed it to mine.
You could get another SD card (I recommend buying a couple identical ones so you can clone a backup easily even if you have made changes, like installing a VPN) and flash it with the latest Full Package image and watch it like a hawk for a few weeks. If that fixes it (and if you have not changed any of the passwords), it's probably not a man in the middle but some glitch in the software. You can also just use the SD card that's in there already, but I am allergic to not having a backup, so I use several. I would keep the original SD unaltered and test again later if it recurs. Maybe it will help troubleshoot this issue.
Maybe I would try to change the login password first, in case that fixes it. Might be an evil maid attack scenario or someone has hacked into your WiFi locally. But why would such a person send hashes to a user name account containing 'Futurebit"? Not really likely.
Installing a VPN on the Full Package Apollo was a bit of an effort for me, much time spent with VPN support staff until someone told me that I can turn the ipv6 off at my WiFi router. Now it's easy (if I follow my notes to paste the right gobbledigook in the right places!

). But I also have backup images (using dd) and ready to go backup SD cards in case something happens. Until a new SD card image gets published by Futurebit, I will use my own images with the modifications made to re-flash the SD if needed.
While you trouble-shoot this, you could run the Apollo as standard unit through your laptop. Then it will be running through your existing VPN without hassles, I think. You simply dis-connect the white cable connector between the Orange Pi and the rest of the Apollo and then connect it to your laptop with a USB cable to the micro-USB port on the Apollo. I don't know if that could be affecting your warranty. The power supply needs to remain connected of course. Some assembly is required, as in: editing a bit of code and unscrewing the Orange Pi and screwing it back on. Or use long nosed pliers.