/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US, the UK, and Cisco warn Russian hacking group APT28 is deploying custom malware on Cisco IOS routers, allowing unauthenticated access to the devices

Lawrence Abrams / BleepingComputer :

BleepingComputer Lawrence Abrams

Context & Ripple Effects

This warning fits a longer record of router backdoors and Russia-linked router malware: a Cisco router backdoor found on dozens of devices preceded Talos’s report of large-scale router infections across dozens of countries.

It also establishes an APT28 router-access pattern that later allied action and UK reporting extend beyond Cisco equipment, from disrupting APT28’s router infrastructure to reported hijacking of consumer and small-business routers.

First-order effects

  • Organizations running Cisco IOS routers face a potential device-integrity incident, because the reported malware can provide access without normal authentication.
  • Cisco and government defenders must help customers identify affected routers and remove unauthorized access paths; affected operators may need to treat router credentials and traffic as exposed.

Second-order effects

  • Network teams are likely to elevate router monitoring, configuration review, and management-plane isolation alongside endpoint security, since compromised infrastructure can sit beneath ordinary user controls.
  • The case increases pressure on router vendors and managed-network providers to make compromise detection and recovery more operationally accessible to customers.

Third-order effects

  • If repeated router campaigns persist, network appliances will be treated less as passive connectivity gear and more as high-value identity and traffic-control assets requiring continuous security operations.
  • The related cross-vendor reporting points toward a broader state-backed focus on edge infrastructure; coordinated disruption may become a recurring complement to vendor-led remediation.

The trend: State-linked intrusion campaigns are increasingly targeting internet-facing network infrastructure to gain durable access and influence over credential and traffic flows.

Discussion

  • @ncsc @ncsc on x
    🚨 Today, on the eve of #CYBERUK23, the UK and US have issued a joint advisory to help organisations counter malicious activity used by Russian cyber actors to exploit poorly maintained Cisco routers 🚨 https://www.ncsc.gov.uk/...
  • @talossecurity @talossecurity on x
    A new state-sponsored campaign called “Jaguar Tooth” is part of a broader trend of adversaries targeting network infrastructure. Here is the latest information Talos has on these attacks and advice on protecting this infrastructure globally https://blog.talosintelligence.com/ ...…