logo

US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers

ID: aa4dac9a-5545-5803-aa2a-ba0158d12055

STIX ID: report--aa4dac9a-5545-5803-aa2a-ba0158d12055

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

...
...

*Executive summary:* APT28 (attributed to Russia's GRU, Unit 26165) conducted a large DNS-hijacking campaign by compromising SOHO routers—notably TP-Link devices—to redirect traffic through attacker-controlled DNS servers and harvest credentials; US and UK authorities detailed the campaign and the DOJ/FBI executed a court-authorized Operation Masquerade to neutralize the US portion of the infrastructure, reset affected routers' DNS settings, coordinate with ISPs, and publish remediation guidance for users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.