logo

GRU Compromises Home Routers in 23 States to Steal Outlook Credentials

ID: 5304689f-6ee7-5848-97cd-6d1811b6f92b

STIX ID: report--5304689f-6ee7-5848-97cd-6d1811b6f92b

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

...
...

The FBI and partners disrupted "Operation Masquerade," a GRU (APT28) campaign that exploited CVE-2023-50224 to hijack TP-Link and MikroTik routers across multiple countries, redirect Outlook web traffic to malicious login pages, and harvest credentials; the campaign impacted thousands of consumer devices (over 5,000 in 23 U.S. states and over 18,000 routers globally at peak) and targeted sensitive sectors, with authorities restoring DNS settings and advising immediate firmware updates and credential changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.