/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The UK says Russia-linked hacking group APT28 is hijacking popular internet routers from MikroTik, TP-Link, and others to steal credentials and redirect traffic

Russian government-linked hackers are compromising popular internet routers to steal passwords for email accounts and other online services …

Bloomberg Ryan Gallagher

Context & Ripple Effects

This is the latest recurrence of APT28’s use of network-edge devices: UK, US and Cisco had already warned that the group deployed custom malware on Cisco IOS routers for unauthenticated access in an earlier router-focused campaign. A 2024 allied operation disrupted the group’s access to more than 1,000 home and small-business routers, showing that taking over the devices has been an operational channel, not a one-off technique.

The renewed focus on MikroTik and TP-Link broadens the immediate concern from a single vendor or device class to commonly deployed routers. It also follows a longer-standing warning that Russia-linked activity targeted internet infrastructure itself, rather than only endpoints or individual accounts.

First-order effects

  • Owners and operators of affected MikroTik, TP-Link and other routers face a live risk that their devices are being used to capture credentials or alter traffic paths, putting the services accessed through those networks at risk.
  • APT28 gains an intermediary position between users and online services when a router is compromised, making credential theft and traffic redirection possible without first compromising each target service.

Second-order effects

  • Router vendors, managed-service providers and small-business IT teams face pressure to identify exposed devices and reduce persistent unauthorized access; the group’s return after the 2024 disruption of access to more than 1,000 routers underscores that disruption alone does not remove the underlying device exposure.
  • Email and other account providers may see more fraud or account-takeover attempts sourced from legitimate-looking user networks, increasing the value of controls that do not treat network location as proof of trust.

Third-order effects

  • If repeated campaigns continue across consumer and small-business networking gear, routers will be treated less as passive connectivity hardware and more as a security-critical identity and traffic-control layer.
  • The pattern favors more sustained public-private monitoring of internet infrastructure and greater accountability for device lifecycle security, though the corpus does not establish what formal requirements vendors or operators will face.

The trend: State-linked actors are increasingly treating widely deployed edge devices as durable access points for credential collection and traffic manipulation.

Discussion

  • @thehackersnews @thehackersnews on x
    🚨 WARNING - APT28 ran a global router hijack to steal credentials. The group compromised MikroTik and TP-Link devices, rewrote DNS settings, and redirected traffic for credential theft at scale — impacting 18,000+ IPs across 120 countries, including government and cloud [image]
  • @baddcompani @baddcompani on x
    APT28! Fancy Bear!
  • @bushidotoken Will on x
    Russian GRU hitting poorly made, badly secured MikroTik and TP-Link routers for intelligence gathering, a familiar story...
  • @ncsc @ncsc on x
    🚨 The UK has exposed Russian military intelligence targeting vulnerable routers to support cyber attacks. A new advisory from the NCSC reveals how state-linked group APT28 exploited vulnerable edge devices to conduct DNS hijacking operations. https://www.ncsc.gov.uk/...
  • @metacurity.com Cynthia Brumfield on bluesky
    Add this development to the growing pile of incredibly imporant cyber security news to know today.  [embedded post]