logo

APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign

ID: 32aaff00-57f8-5619-9269-e2f2dc0ec2e8

STIX ID: report--32aaff00-57f8-5619-9269-e2f2dc0ec2e8

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-08

...
...

Russian-linked APT28 (Fancy Bear) has exploited vulnerabilities in TP-Link and MikroTik routers—including CVE-2023-50224—to hijack DNS on over 18,000 devices across 120 countries, enabling interception of traffic and credential/token theft against military, government, and critical infrastructure targets; authorities (DOJ/FBI) executed a takedown called Operation Masquerade and vendors/security agencies have issued advisories urging immediate patching and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.