Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’
ID: c317834a-b40c-505f-b157-35583033f7ea
STIX ID: report--c317834a-b40c-505f-b157-35583033f7ea
Feed Name: CyberScoop
Threat Score
The FBI executed Operation Masquerade to disrupt an APT28 (Russian GRU) campaign that compromised more than 18,000 TP-Link routers and impacted over 200 organizations worldwide by changing routers' DNS to route traffic through malicious IPs; the operation reset DNS settings and removed attacker capabilities from affected devices, continuing prior takedowns of router-focused botnets such as VPNFilter and Cyclops Blink.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
