Russian Cyber Threats Targeting Consumer Routers
ID: 61305c75-6326-5df0-94d1-cd9955d0ef0d
STIX ID: report--61305c75-6326-5df0-94d1-cd9955d0ef0d
Feed Name: ThreatCluster
Threat Score
In 2026 U.S. cybersecurity agencies disrupted a botnet of consumer SOHO routers allegedly operated by Russian intelligence that was being used to steal sensitive information and intercept internet traffic; the NSA and FBI urged users to restart routers and follow mitigations such as changing default passwords, disabling remote management, updating firmware, and replacing unsupported devices to disrupt malware persistence and reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
