logo

Russian hackers hijack internet traffic using vulnerable routers

ID: 4a3a3651-fd07-5230-a1c8-0b5ec061aa2c

STIX ID: report--4a3a3651-fd07-5230-a1c8-0b5ec061aa2c

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-28

Author: Sinisa Markovic

...
...

The UK NCSC warns that APT28 (linked to the Russian GRU) has been compromising SOHO routers—including TP-Link WR841N via CVE-2023-50224—to modify DHCP/DNS settings and route traffic through attacker-controlled DNS servers, enabling man-in-the-middle interception of browser sessions and authentication data; investigators identified two clusters of malicious DNS infrastructure and recommend following the advisory's mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.