logo

Russian hackers hijack Ubiquiti routers to launch stealthy attacks

ID: f1e6aa29-105e-57cd-9d7f-a24c1890df54

STIX ID: report--f1e6aa29-105e-57cd-9d7f-a24c1890df54

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-02-27

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

U.S. and allied agencies warn that Russian APT28 (Fancy Bear) has been abusing compromised Ubiquiti EdgeRouters—often left with default credentials and no automatic updates—to build botnets that harvest credentials (including NTLMv2), proxy malicious traffic, host phishing pages, and deploy custom espionage tooling; the advisory details observed artifacts, recent FBI disruption actions, and remediation steps (factory reset, firmware update, change defaults, and WAN firewall rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.