Russian Hackers Target Routers to Steal Sensitive Data
ID: e3486ae8-af24-58d7-bb49-49954fac6684
STIX ID: report--e3486ae8-af24-58d7-bb49-49954fac6684
Feed Name: ThreatCluster
Threat Score
FBI and NSA warnings indicate Russian GRU-linked APT28 is actively exploiting vulnerabilities in SOHO routers (notably older TP‑Link devices) to hijack devices and steal sensitive data including passwords and authentication tokens; Microsoft reported impacts to over 200 organizations and roughly 5,000 consumer devices. Users are advised to change default passwords, update firmware, and apply security best practices to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
