APT28 Disrupts Router DNS to Steal Microsoft Credentials in Global Campaign
ID: 570dc01b-33f9-578b-bf91-9bb991efe931
STIX ID: report--570dc01b-33f9-578b-bf91-9bb991efe931
Feed Name: ThreatCluster
APT28 (linked to the GRU) conducted the FrostArmada campaign that hijacked DNS settings on vulnerable MikroTik and TP‑Link routers—exploiting CVE-2023-50224—to perform adversary-in-the-middle attacks and harvest Microsoft credentials from approximately 18,000 devices across 120 countries, primarily targeting government and IT sectors; the infrastructure was disrupted by an international operation supported by Microsoft, the FBI and other agencies, and the UK NCSC warned organizations to secure routers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
