logo

FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks

ID: 47809853-424d-5fb2-ac5f-b55f48a4a549

STIX ID: report--47809853-424d-5fb2-ac5f-b55f48a4a549

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

APT28 (GRU Unit 26165) conducted large-scale DNS hijacking by exploiting vulnerabilities in SOHO/TP-Link routers to redirect DNS traffic through malicious resolvers, enabling adversary‑in‑the‑middle interception of credentials and email data—particularly targeting Microsoft Outlook-related services; U.S. authorities (DOJ/FBI) executed Operation Masquerade to disrupt the U.S. portion of the infrastructure, restore router DNS settings, and issued mitigation recommendations including firmware updates, router replacement, and enabling MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.