Cnet GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
Article Content
- •GRU exploited CVE-2023-50224 to hijack routers and steal Outlook credentials.
- •Over 5,000 consumer devices in 23 states were compromised in this operation.
- •Immediate action is recommended for router owners to secure their devices.
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that over 5,000 consumer devices across 23 states were affected, with the attack leveraging CVE-2023-50224, an authentication bypass flaw. The GRU hijacked routers by altering DNS settings, redirecting users to fake login pages without their knowledge. The operation began in August 2025 and peaked in December 2025, impacting over 200 organizations globally. Authorities have urged immediate action to secure routers, including firmware updates and changing default credentials. The UK National Cyber Security Centre confirmed the campaign's opportunistic nature, targeting individuals in sensitive sectors. The FBI's intervention involved restoring legitimate configurations on compromised devices without accessing user data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track APT28, TP-Link and CVE-2023-50224 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Trellix Reports on Five Evasive Cyber Campaigns in 2026 Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts and weaponizing…
2026 AV-Comparatives EPR Test Results Released AV-Comparatives published the results of its 2026 Endpoint Prevention and Response (EPR) Test, evaluating 14 enterprise security products against 50 multi-stage attack scenarios. The test, which ran from May to August 2026, incorporated AI-assisted techniques and followed the MITRE ATT&CK framework. Eleven products…