logo

APT28 Disrupts Router DNS to Steal Microsoft Credentials in Global Campaign

ID: 570dc01b-33f9-578b-bf91-9bb991efe931

STIX ID: report--570dc01b-33f9-578b-bf91-9bb991efe931

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-07

...
...

APT28 (linked to the GRU) conducted the FrostArmada campaign that hijacked DNS settings on vulnerable MikroTik and TP‑Link routers—exploiting CVE-2023-50224—to perform adversary-in-the-middle attacks and harvest Microsoft credentials from approximately 18,000 devices across 120 countries, primarily targeting government and IT sectors; the infrastructure was disrupted by an international operation supported by Microsoft, the FBI and other agencies, and the UK NCSC warned organizations to secure routers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.