Russian hacking group targets home and small office routers to spy on users
ID: dcaccd76-850b-5dae-b7d1-282536b5dc3d
STIX ID: report--dcaccd76-850b-5dae-b7d1-282536b5dc3d
Feed Name: Malwarebytes Blog
APT28 (aka Fancy Bear/Forest Blizzard) is exploiting vulnerabilities in consumer SOHO routers—particularly TP-Link models like WR841N—to change DNS settings and silently route victims' traffic through attacker-controlled servers, allowing harvesting of passwords, authentication tokens, and interception of Microsoft 365 and other cloud traffic. Microsoft and UK/US agencies report thousands of affected consumer devices and over 200 impacted organizations; the report includes detection steps (verify DHCP/DNS against ISP expectations), mitigations (change defaults, update firmware, disable remote management, consider open‑source firmware), and guidance to report suspected compromises to the FBI/IC3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
