The UK says Russia-linked hacking group APT28 is hijacking popular internet routers from MikroTik, TP-Link, and others to steal credentials and redirect traffic
Russian government-linked hackers are compromising popular internet routers to steal passwords for email accounts and other online services …
Bloomberg Ryan Gallagher
Related Coverage
- SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks Microsoft Security Blog
- APT28 exploit routers to enable DNS hijacking operations NCSC.GOV.UK
- FrostArmada: All thriller, no (malware) filler Lumen Technologies
- Germany Intelligence Warns TP-Link Routers Exploited By Russian Hackers To Spy On Military And Critical Infrastructure Benzinga · Ananya Gairola
- Russian military hackers reroute British internet users' traffic Financial Times · Charles Clover
- Elite Russian hackers are hijacking British internet users' traffic Mirror · Eliana Nunes
- Russian government hackers broke into thousands of home routers to steal passwords TechCrunch · Lorenzo Franceschi-Bicchierai
- UK exposes Russian cyber unit hacking home routers to hijack internet traffic The Record · Alexander Martin
- FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks The Cyber Express · Ashish Khaitan
- Russia Hacked Routers to Steal Microsoft Office Tokens Krebs on Security · Brian Krebs
- Germany intelligence agency warns of Russian APT28 cyber spying Reuters · Maria Martinez
- Russian hackers hijack internet traffic using vulnerable routers Help Net Security · Sinisa Markovic
- Russia's GRU hacked cheap routers across the Global South to harvest government credentials at scale Silicon Canals · Tommy Baker
- NCSC issues alert over Russian hacker campaign targeting SOHO routers ITPro · Emma Woollacott
- ‘This puts organizations at risk of credential theft, data manipulation and broader compromise’: UK government, Microsoft warn Russian hackers … TechRadar · Sead Fadilpašić
- Russian hackers are ‘hijacking wifi routers to steal passwords’ Metro.co.uk · Craig Munro
- How Russia's GRU turned $50 routers into a global intelligence platform spanning 120 countries Silicon Canals · Christian Kelly
- Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins BleepingComputer · Bill Toulas
- Russian GRU hackers are hijacking TP-Link and MikroTik routers to steal Outlook credentials, cybersecurity center warns … Tom's Hardware · Luke James
- Russian Forest Blizzard Hackers Hijack Home Routers for Global Spying Hackread · Deeba Ahmed
- Authorities disrupt DNS hijacking campaign targeting TP-Link routers CyberInsider · Alex Lekander
- Britons warned about Russian hackers targeting internet routers for espionage The Guardian · Aisha Down
- Thousands of consumer routers hacked by Russia's military Ars Technica · Dan Goodin
- Home and office routers across US were targets of Russian hackers, Boston FBI office says The Boston Globe · Tonya Alanez
- Feds quash widespread Russia-backed espionage network spanning 18,000 devices CyberScoop · Matt Kapko
- I'm excited to release a report that I've been working on for the past year, Forest Blizzard's hacking of SoHo routers to abuse the DNS ecosystem. … Danny A.
Discussion
-
@thehackersnews
@thehackersnews
on x
🚨 WARNING - APT28 ran a global router hijack to steal credentials. The group compromised MikroTik and TP-Link devices, rewrote DNS settings, and redirected traffic for credential theft at scale — impacting 18,000+ IPs across 120 countries, including government and cloud [image]
-
@baddcompani
@baddcompani
on x
APT28! Fancy Bear!
-
@bushidotoken
Will
on x
Russian GRU hitting poorly made, badly secured MikroTik and TP-Link routers for intelligence gathering, a familiar story...
-
@ncsc
@ncsc
on x
🚨 The UK has exposed Russian military intelligence targeting vulnerable routers to support cyber attacks. A new advisory from the NCSC reveals how state-linked group APT28 exploited vulnerable edge devices to conduct DNS hijacking operations. https://www.ncsc.gov.uk/...
-
@metacurity.com
Cynthia Brumfield
on bluesky
Add this development to the growing pile of incredibly imporant cyber security news to know today. [embedded post]