APT28 Uses Compromised Routers to Steal Credentials via DNS Hijacking
APT28 is exploiting vulnerable internet edge routers to create persistent DNS interception points. This allows them to silently redirect DNS traffic and harvest credentials and access tokens from personal web and email services. The routers themselves are not the final target; they serve as infrastructure for attackers to pivot into higher-value accounts later. The UK NCSC advisory describes this campaign as opportunistic, with attackers sweeping broadly across exposed devices before focusing on intelligence targets. This means the blast radius extends beyond the device owner to any users whose DNS traffic is intercepted. Standard perimeter defenses miss this risk because attackers do not need to compromise endpoints or identity systems directly if they control DNS at the network edge. This campaign demands attention from network security teams managing internet routers and edge devices, especially those with exposed remote management or decentralized branch networks. Identity teams, a
14 sources · Apr 13
Community Assessment
Government advisory confirms APT28 targeted vulnerable routers for DNS hijacking to support credential theft; security media add that thousands of consumer and edge devices were used to reroute Microsoft 365 traffic through AiTM proxies, with reported impact across 18,000+ IPs in 120 countries.
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’
FBI Assistant Director Brett Leatherman reveals how "Operation Masquerade" dismantled a "virtually invisible" Russian GRU cyber campaign that hijacked 18,000 routers to spy on home and office traffic worldwide.