logo

Russians hijacking routers for cyber spying

ID: 02b076d2-c549-5329-99ca-2cc9251e28ac

STIX ID: report--02b076d2-c549-5329-99ca-2cc9251e28ac

Feed Name: DataBreaches.Net

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-19

Author: Dissent

...
...

The IC3/NCSC advisory describes APT28 (Russian GRU, 85th GTsSS) exploiting vulnerable small-office/home-office and edge routers since at least 2024 to change DHCP/DNS settings, direct victims to actor-controlled resolvers, and conduct DNS hijacking and AitM attacks that have harvested passwords, authentication tokens, emails, and browsing data. U.S. DOJ and FBI disrupted part of the GRU router network; international partners issued guidance to update firmware, change default credentials, disable remote management, review remote-access policies, and report suspected compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.