logo

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

ID: a3379645-48cd-558c-a900-bcf3c9d3d9af

STIX ID: report--a3379645-48cd-558c-a900-bcf3c9d3d9af

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft and Lumen Black Lotus Labs attribute a widespread campaign called FrostArmada to APT28 (Forest Blizzard), which since May 2025 has exploited insecure MikroTik and TP-Link SOHO routers—including likely abuse of CVE-2023-50224—to change DNS resolvers and perform DNS hijacking and AiTM interceptions that harvested credentials and OAuth tokens from targeted government agencies and service providers; the infrastructure contacted over 18,000 unique IPs across 120+ countries before being disrupted in a multinational law enforcement operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.