Russian hackers hijack internet traffic using vulnerable routers
ID: 4a3a3651-fd07-5230-a1c8-0b5ec061aa2c
STIX ID: report--4a3a3651-fd07-5230-a1c8-0b5ec061aa2c
Feed Name: Help Net Security
Threat Score
The UK NCSC warns that APT28 (linked to the Russian GRU) has been compromising SOHO routers—including TP-Link WR841N via CVE-2023-50224—to modify DHCP/DNS settings and route traffic through attacker-controlled DNS servers, enabling man-in-the-middle interception of browser sessions and authentication data; investigators identified two clusters of malicious DNS infrastructure and recommend following the advisory's mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
