logo

Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns

ID: 8a3d6f93-3783-5fbb-846c-8264b7c67f15

STIX ID: report--8a3d6f93-3783-5fbb-846c-8264b7c67f15

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

...
...

**APT28 (GRU-linked) has been observed compromising SOHO routers (mainly TP-Link and MikroTik) to change DHCP/DNS settings so that victim traffic is resolved via actor-controlled VPS DNS servers; this enables adversary-in-the-middle operations to harvest credentials, tokens, and other sensitive data, with CVE-2023-50224 implicated against TP-Link WR841N and targeted operations against MikroTik devices.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.