Russians hijacking routers for cyber spying
ID: 02b076d2-c549-5329-99ca-2cc9251e28ac
STIX ID: report--02b076d2-c549-5329-99ca-2cc9251e28ac
Feed Name: DataBreaches.Net
The IC3/NCSC advisory describes APT28 (Russian GRU, 85th GTsSS) exploiting vulnerable small-office/home-office and edge routers since at least 2024 to change DHCP/DNS settings, direct victims to actor-controlled resolvers, and conduct DNS hijacking and AitM attacks that have harvested passwords, authentication tokens, emails, and browsing data. U.S. DOJ and FBI disrupted part of the GRU router network; international partners issued guidance to update firmware, change default credentials, disable remote management, review remote-access policies, and report suspected compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
