logo

APT28 Hijacks Routers to Steal Credentials in Global Cyber Espionage Campaign

ID: 2401e724-9785-5baa-8761-4dc40f0796e0

STIX ID: report--2401e724-9785-5baa-8761-4dc40f0796e0

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-08

...
...

APT28 (Russian state-sponsored) conducted the FrostArmada campaign by exploiting CVE-2023-50224 in MikroTik and TP-Link consumer/SOHO routers to hijack DNS settings and redirect traffic, enabling adversary-in-the-middle attacks to steal login credentials and authentication tokens from over 18,000 devices in 120 countries; UK NCSC and Microsoft collaborated to disrupt the operation and issued mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.