APT28 is exploiting vulnerable internet edge routers to create persistent DNS interception points. This allows them to silently redirect DNS traffic and harvest credentials and access tokens from personal web and email services. The routers themselves are not the final target; they serve as infrastructure for attackers to pivot into higher-value accounts later. The UK NCSC advisory describes this campaign as opportunistic, with attackers sweeping broadly across exposed devices before focusing on intelligence targets. This means the blast radius extends beyond the device owner to any users whose DNS traffic is intercepted. Standard perimeter defenses miss this risk because attackers do not need to compromise endpoints or identity systems directly if they control DNS at the network edge. This campaign demands attention from network security teams managing internet routers and edge devices, especially those with exposed remote management or decentralized branch networks. Identity teams, a
Part of the PlainSec briefing for 2026-04-07