Threats · 155 days ago
APT28 is exploiting vulnerable internet edge routers to create persistent DNS interception points. This allows them to silently redirect DNS traffic and harvest credentials and access tokens from personal web and email services. The routers themselves are not the final target; they serve as infrastructure for attackers to pivot into higher-value accounts later. The UK NCSC advisory describes this campaign as opportunistic, with attackers sweeping broadly across exposed devices before focusing on intelligence targets. This means the blast radius extends beyond the device owner to any users whose DNS traffic is intercepted. Standard perimeter defenses miss this risk because attackers do not need to compromise endpoints or identity systems directly if they control DNS at the network edge. This campaign demands attention from network security teams managing internet routers and edge devices, especially those with exposed remote management or decentralized branch networks. Identity teams, a
14 sources covering this story
New UK NCSC advisory discloses that APT28 hackers exploit routers for DNS hijacking, enabling large-scale traffic interception.
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’
FBI Assistant Director Brett Leatherman reveals how "Operation Masquerade" dismantled a "virtually invisible" Russian GRU cyber campaign that hijacked 18,000 routers to spy on home and office traffic worldwide.
Russia's Forest Blizzard Nabs Rafts of Logins via SOHO Routers
Russia is spying on global organizations by modifying just one DNS setting in vulnerable routers.
US operation evicts Russia from hacked SOHO routers used to breach critical infrastructure
The newly disclosed cyberattack campaign is the latest evidence of the threat end-of-life routers pose to major organizations.
US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking
The APT28 threat group exploited vulnerable TP-Link and MikroTik routers to conduct adversary-in-the-middle (AitM) attacks.
US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers
The FBI deployed a method to unplug US-based routers compromised by APT28 from the threat actor’s malicious network
Feds quash widespread Russia-backed espionage network spanning 18,000 devices
Forest Blizzard, a threat group attributed to Russia’s GRU, hijacked network traffic to steal credentials and tokens for Microsoft accounts and other services.
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
APT28 exploits SOHO routers for global DNS hijacking and adversary-in-the-middle attacks, enabling credential theft and espionage.
Russia Hacked Routers to Steal Microsoft Office Tokens
Hackers linked to Russia's military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today.
Russia's APT28 behind latest wave of router, DNS attacks
: 200 orgs and 5,000 devices compromised so far in Vlad's latest intelligence grab, Microsoft reckons
Russian government hackers broke into thousands of home routers to steal passwords | TechCrunch
Fancy Bear, also known as APT28, has taken over thousands of residential home routers to steal passwords and authentication tokens in a wide-ranging espionage operation.
Russian hackers hijack internet traffic using vulnerable routers - Help Net Security
Russian hackers used router hijacking to redirect internet traffic through malicious DNS servers, enabling credential theft.
Part of the PlainSec briefing for 2026-04-07