/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The UK says Russia-linked hacking group APT28 is hijacking popular internet routers from MikroTik, TP-Link, and others to steal credentials and redirect traffic

Russian government-linked hackers are compromising popular internet routers to steal passwords for email accounts and other online services …

Bloomberg Ryan Gallagher

Context & Ripple Effects

APT28's use of network infrastructure is a recurring pattern rather than an isolated credential-theft campaign. In 2023, US and UK authorities and Cisco warned that the group had placed custom malware on Cisco IOS routers to enable unauthenticated access; the new UK finding extends that router-focused playbook across widely used devices, including MikroTik and TP-Link.

The report also follows a [[a:849424|2024 allied operation that disrupted APT28's access to more than 1,000 home and small-business routers]]. That sequence matters because disruption can remove known footholds without eliminating the incentives or weaknesses that make edge devices useful for covert traffic interception and account compromise.

First-order effects

  • Owners and operators of affected routers face an immediate exposure: compromised devices can be used to capture credentials and alter where users' traffic goes, making the router itself a security incident rather than merely a connectivity problem.
  • MikroTik, TP-Link, and other named vendors face renewed pressure to help customers identify compromise, remediate vulnerable deployments, and make secure configuration and updates easier to execute.

Second-order effects

  • Organizations that rely on small-office, home, or distributed-site routers will need to treat network-edge monitoring, credential resets, and traffic-integrity checks as linked response tasks; a clean endpoint alone may not establish that user sessions were safe.
  • The campaign reinforces the operational lesson from the earlier APT28 malware activity on Cisco IOS routers: vendors and defenders cannot limit router-focused threat detection to one manufacturer or device class.

Third-order effects

  • If state-linked groups continue to repurpose mass-market routers after takedowns, internet edge equipment will increasingly be managed as critical identity and traffic-control infrastructure, not low-touch commodity hardware.
  • The durable shift is toward security expectations that span a device's lifecycle—patch availability, secure defaults, visibility, and recovery—though the corpus does not establish which vendors or regulators will impose those requirements.

The trend: This is another data point in the migration of espionage-oriented operations toward broadly deployed edge devices that can quietly control both network paths and access credentials.

Discussion

  • @baddcompani @baddcompani on x
    APT28! Fancy Bear!
  • @bushidotoken Will on x
    Russian GRU hitting poorly made, badly secured MikroTik and TP-Link routers for intelligence gathering, a familiar story...
  • @ncsc @ncsc on x
    🚨 The UK has exposed Russian military intelligence targeting vulnerable routers to support cyber attacks. A new advisory from the NCSC reveals how state-linked group APT28 exploited vulnerable edge devices to conduct DNS hijacking operations. https://www.ncsc.gov.uk/...
  • @thehackersnews @thehackersnews on x
    🚨 WARNING - APT28 ran a global router hijack to steal credentials. The group compromised MikroTik and TP-Link devices, rewrote DNS settings, and redirected traffic for credential theft at scale — impacting 18,000+ IPs across 120 countries, including government and cloud [image]
  • @metacurity.com Cynthia Brumfield on bluesky
    Add this development to the growing pile of incredibly imporant cyber security news to know today.  [embedded post]