APT28 Hijacks Home Routers to Steal Corporate Credentials
ID: f6a67b41-fd1a-5470-827a-92faf49aab68
STIX ID: report--f6a67b41-fd1a-5470-827a-92faf49aab68
Feed Name: securityonline.info
The UK NCSC reports that Russian APT28 is conducting a global campaign exploiting consumer routers (notably MikroTik and TP-Link) by overwriting DHCP/DNS settings — often via CVE-2023-50224 — to redirect users to malicious clones of legitimate sites, enabling adversary-in-the-middle DNS hijacking that harvests passwords and OAuth tokens; the disclosure identifies targeted clusters (including activity against Ukraine) and recommends patching firmware, changing default credentials, and monitoring DNS traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
