Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign
ID: a07e01dd-a57d-5db1-94ed-1d09e547cbe9
STIX ID: report--a07e01dd-a57d-5db1-94ed-1d09e547cbe9
Feed Name: HackRead
The U.S. Department of Justice and FBI disrupted "Operation Masquerade," a Russian GRU (APT28/Fancy Bear) cyberespionage campaign that leveraged known TP-Link router vulnerabilities to perform DNS hijacking on thousands of devices across 23 U.S. states and other countries, serving fake login pages (e.g., counterfeit Outlook Web Access) to steal credentials and tokens; the FBI used a court order to remotely reset routers' DNS and blocked the attackers while coordinating with Microsoft Threat Intelligence, MIT Lincoln Laboratory, and Black Lotus Labs, and advised users to update or replace affected routers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
