The UK says Russia-linked hacking group APT28 is hijacking popular internet routers from MikroTik, TP-Link, and others to steal credentials and redirect traffic
Russian government-linked hackers are compromising popular internet routers to steal passwords for email accounts and other online services …
Context & Ripple Effects
This is the latest recurrence of APT28’s use of network-edge devices: UK, US and Cisco had already warned that the group deployed custom malware on Cisco IOS routers for unauthenticated access in an earlier router-focused campaign. A 2024 allied operation disrupted the group’s access to more than 1,000 home and small-business routers, showing that taking over the devices has been an operational channel, not a one-off technique.
The renewed focus on MikroTik and TP-Link broadens the immediate concern from a single vendor or device class to commonly deployed routers. It also follows a longer-standing warning that Russia-linked activity targeted internet infrastructure itself, rather than only endpoints or individual accounts.
First-order effects
- Owners and operators of affected MikroTik, TP-Link and other routers face a live risk that their devices are being used to capture credentials or alter traffic paths, putting the services accessed through those networks at risk.
- APT28 gains an intermediary position between users and online services when a router is compromised, making credential theft and traffic redirection possible without first compromising each target service.
Second-order effects
- Router vendors, managed-service providers and small-business IT teams face pressure to identify exposed devices and reduce persistent unauthorized access; the group’s return after the 2024 disruption of access to more than 1,000 routers underscores that disruption alone does not remove the underlying device exposure.
- Email and other account providers may see more fraud or account-takeover attempts sourced from legitimate-looking user networks, increasing the value of controls that do not treat network location as proof of trust.
Third-order effects
- If repeated campaigns continue across consumer and small-business networking gear, routers will be treated less as passive connectivity hardware and more as a security-critical identity and traffic-control layer.
- The pattern favors more sustained public-private monitoring of internet infrastructure and greater accountability for device lifecycle security, though the corpus does not establish what formal requirements vendors or operators will face.
The trend: State-linked actors are increasingly treating widely deployed edge devices as durable access points for credential collection and traffic manipulation.