Russian Threat Actors Abuse Home Routers in Expanding DNS Hijacking Wave
ID: 2116a379-60ff-5973-b5a9-b1694444b741
STIX ID: report--2116a379-60ff-5973-b5a9-b1694444b741
Feed Name: GBHackers
Russian state-linked APT 'Forest Blizzard' (also tracked as APT28/Strontium) has been compromising insecure home and small-office routers since August 2025 to modify DNS settings and forward traffic through attacker-controlled infrastructure using dnsmasq; this enables broad passive network visibility and selective Adversary-in-the-Middle attacks against high-value targets in government, IT, and energy sectors, with the campaign reportedly impacting over 200 organizations and 5,000 consumer devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
