Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns
ID: 52f9c1ed-5f99-5c66-8c61-8a5af5086f46
STIX ID: report--52f9c1ed-5f99-5c66-8c61-8a5af5086f46
Feed Name: The Register (Security)
Threat Score
The UK NCSC and Microsoft warn that Russia-linked APT28 (Fancy Bear) has been exploiting vulnerabilities in SOHO and enterprise routers (TP-Link, Cisco, MikroTik) to hijack DNS settings, redirect victims to credential-phishing sites, and deploy backdoors (e.g., Jaguar Tooth); Microsoft reported over 200 organizations and 5,000 consumer devices impacted, and the activity has been monitored since 2021.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
