Related Threat Clusters
-
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026
Recent Intelligence Reports
- ReliaQuest — reliaquest.com · August 5, 2026
- FrostArmada — www.lumen.com · August 3, 2026
- Hackers hijack hotel Wi — Bleepingcomputer · July 24, 2026
- FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years — Techtimes · July 13, 2026
- US and allies warn of Russian critical infrastructure attacks — Bleepingcomputer · July 13, 2026
- GRU Hijacked TP-Link Routers in 23 States to Steal Outlook Passwords: FBI Urges Immediate Action — Techtimes · May 21, 2026
- Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins — Ground.News · April 7, 2026