FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks
ID: 47809853-424d-5fb2-ac5f-b55f48a4a549
STIX ID: report--47809853-424d-5fb2-ac5f-b55f48a4a549
Feed Name: The Cyber Express
APT28 (GRU Unit 26165) conducted large-scale DNS hijacking by exploiting vulnerabilities in SOHO/TP-Link routers to redirect DNS traffic through malicious resolvers, enabling adversary‑in‑the‑middle interception of credentials and email data—particularly targeting Microsoft Outlook-related services; U.S. authorities (DOJ/FBI) executed Operation Masquerade to disrupt the U.S. portion of the infrastructure, restore router DNS settings, and issued mitigation recommendations including firmware updates, router replacement, and enabling MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
