logo

Russia's Forest Blizzard Nabs Rafts of Logins via SOHO Routers

ID: 948f3d02-bdf4-5357-9a4b-dffa4f715d4c

STIX ID: report--948f3d02-bdf4-5357-9a4b-dffa4f715d4c

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Nate Nelson

...
...

A GRU-linked APT28 subgroup has been intercepting web traffic by exploiting old vulnerabilities in SOHO routers (MikroTik, TP-Link and others) to change DNS and route victim requests through attacker-operated VPS, enabling credential theft from email and web services; researchers observed thousands of affected IPs and hundreds of organizations worldwide and the U.S. DOJ executed a disruption called Operation Masquerade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.