Threats & Adversaries · APT / Espionage

APT28 Uses Compromised Routers to Steal Credentials via DNS Hijacking

APT28 is exploiting vulnerable internet edge routers to create persistent DNS interception points. This allows them to silently redirect DNS traffic and harvest credentials and access tokens from personal web and email services. The routers themselves are not the final target; they serve as infrastructure for attackers to pivot into higher-value accounts later. The UK NCSC advisory describes this campaign as opportunistic, with attackers sweeping broadly across exposed devices before focusing on intelligence targets. This means the blast radius extends beyond the device owner to any users whose DNS traffic is intercepted. Standard perimeter defenses miss this risk because attackers do not need to compromise endpoints or identity systems directly if they control DNS at the network edge. This campaign demands attention from network security teams managing internet routers and edge devices, especially those with exposed remote management or decentralized branch networks. Identity teams, a

14 sources · Apr 13

Community Assessment

Government advisory confirms APT28 targeted vulnerable routers for DNS hijacking to support credential theft; security media add that thousands of consumer and edge devices were used to reroute Microsoft 365 traffic through AiTM proxies, with reported impact across 18,000+ IPs in 120 countries.

Timeline

Sources

Part of the PlainSec briefing for 2026-04-07

Every edition of this story: APT28 Uses Compromised Routers to Steal Credentials via DNS Hijacking

More from today