APT28 Uses Consumer Routers to Steal Credentials at Scale
Consumer MikroTik and TP-Link routers are being hijacked by APT28 to intercept credentials without compromising endpoints or servers. The attackers manipulate DNS and DHCP settings to redirect users to credential-harvesting sites, turning the network path itself into a silent espionage vector. This breaks the usual assumption that endpoint or server compromise is required to steal session tokens or passwords.
Researchers estimate 18,000 to 40,000 routers in 120 countries are affected, with some routers acting as proxies to reach government, law enforcement, and foreign ministry targets. The campaign is active and widespread, leveraging unpatched consumer routers to proxy traffic and alter name resolution for targeted espionage. Microsoft confirmed domains for its 365 service were among those manipulated.
This campaign demands urgent attention from government and national-security organizations relying on remote or partner-managed consumer routers. The risk persists beyond patching because the attack exploits network infrastructure rather than software vulnerabilities on endpoints or servers. Awareness and containment of exposed routers are critical to mitigating credential theft in this scenario.