APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Article Content
- •APT28 has compromised over 18,000 routers globally, targeting sensitive sectors.
- •The group exploits vulnerabilities in TP-Link and MikroTik routers to hijack DNS traffic.
- •Operation Masquerade successfully disrupted a significant portion of APT28's infrastructure.
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000 devices across 120 countries, allows attackers to intercept internet traffic and steal sensitive information, including passwords and access tokens. The group has been leveraging known vulnerabilities, such as CVE-2023-50224, to modify DNS settings and redirect users to malicious servers. The U.S. Department of Justice and FBI recently announced the takedown of a significant portion of this infrastructure in an operation dubbed 'Operation Masquerade.' The attacks have primarily targeted military, government, and critical infrastructure sectors. Authorities are urging users to update their devices and follow security best practices to mitigate risks. The NCSC and Microsoft have issued advisories detailing the ongoing threat and the need for immediate action.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (100)
Following this threat?
Track Apt28, Authentic Antics and Democratic National Committee in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability in Zimbra Exploited by Attackers A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers to execute arbitrary commands as the Zimbra user through improper input sanitization in SNMP…
Russia's Hybrid Warfare Threatens UK with Cyberattacks and Sabotage Russia has escalated threats against the UK following its support for Ukraine, warning of 'consequences' for British involvement. Concurrently, Russian-linked cyberattacks, including a ransomware attack on the pathology lab Synnovis, have severely disrupted NHS services in London, affecting over 800 operations and 700…