The UK says Russia-linked hacking group APT28 is hijacking popular internet routers from MikroTik, TP-Link, and others to steal credentials and redirect traffic
Russian government-linked hackers are compromising popular internet routers to steal passwords for email accounts and other online services …
Context & Ripple Effects
APT28's use of network infrastructure is a recurring pattern rather than an isolated credential-theft campaign. In 2023, US and UK authorities and Cisco warned that the group had placed custom malware on Cisco IOS routers to enable unauthenticated access; the new UK finding extends that router-focused playbook across widely used devices, including MikroTik and TP-Link.
The report also follows a [[a:849424|2024 allied operation that disrupted APT28's access to more than 1,000 home and small-business routers]]. That sequence matters because disruption can remove known footholds without eliminating the incentives or weaknesses that make edge devices useful for covert traffic interception and account compromise.
First-order effects
- Owners and operators of affected routers face an immediate exposure: compromised devices can be used to capture credentials and alter where users' traffic goes, making the router itself a security incident rather than merely a connectivity problem.
- MikroTik, TP-Link, and other named vendors face renewed pressure to help customers identify compromise, remediate vulnerable deployments, and make secure configuration and updates easier to execute.
Second-order effects
- Organizations that rely on small-office, home, or distributed-site routers will need to treat network-edge monitoring, credential resets, and traffic-integrity checks as linked response tasks; a clean endpoint alone may not establish that user sessions were safe.
- The campaign reinforces the operational lesson from the earlier APT28 malware activity on Cisco IOS routers: vendors and defenders cannot limit router-focused threat detection to one manufacturer or device class.
Third-order effects
- If state-linked groups continue to repurpose mass-market routers after takedowns, internet edge equipment will increasingly be managed as critical identity and traffic-control infrastructure, not low-touch commodity hardware.
- The durable shift is toward security expectations that span a device's lifecycle—patch availability, secure defaults, visibility, and recovery—though the corpus does not establish which vendors or regulators will impose those requirements.
The trend: This is another data point in the migration of espionage-oriented operations toward broadly deployed edge devices that can quietly control both network paths and access credentials.