Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns
ID: 8a3d6f93-3783-5fbb-846c-8264b7c67f15
STIX ID: report--8a3d6f93-3783-5fbb-846c-8264b7c67f15
Feed Name: Infosecurity Magazine (News)
Threat Score
**APT28 (GRU-linked) has been observed compromising SOHO routers (mainly TP-Link and MikroTik) to change DHCP/DNS settings so that victim traffic is resolved via actor-controlled VPS DNS servers; this enables adversary-in-the-middle operations to harvest credentials, tokens, and other sensitive data, with CVE-2023-50224 implicated against TP-Link WR841N and targeted operations against MikroTik devices.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
