US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers
ID: aa4dac9a-5545-5803-aa2a-ba0158d12055
STIX ID: report--aa4dac9a-5545-5803-aa2a-ba0158d12055
Feed Name: Infosecurity Magazine (News)
*Executive summary:* APT28 (attributed to Russia's GRU, Unit 26165) conducted a large DNS-hijacking campaign by compromising SOHO routers—notably TP-Link devices—to redirect traffic through attacker-controlled DNS servers and harvest credentials; US and UK authorities detailed the campaign and the DOJ/FBI executed a court-authorized Operation Masquerade to neutralize the US portion of the infrastructure, reset affected routers' DNS settings, coordinate with ISPs, and publish remediation guidance for users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
