logo

Russian Threat Actors Abuse Home Routers in Expanding DNS Hijacking Wave

ID: 2116a379-60ff-5973-b5a9-b1694444b741

STIX ID: report--2116a379-60ff-5973-b5a9-b1694444b741

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Divya

...
...

Russian state-linked APT 'Forest Blizzard' (also tracked as APT28/Strontium) has been compromising insecure home and small-office routers since August 2025 to modify DNS settings and forward traffic through attacker-controlled infrastructure using dnsmasq; this enables broad passive network visibility and selective Adversary-in-the-Middle attacks against high-value targets in government, IT, and energy sectors, with the campaign reportedly impacting over 200 organizations and 5,000 consumer devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.