MikroTik is a technology platform tracked by ThreatCluster, appearing in 10 threat clusters built from 16 intelligence report mentions.
MikroTik is a technology platform tracked across 10 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed April 7, 2026; most recent activity July 25, 2026.
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
GreyNoise Intelligence has released a report indicating that spikes in malicious activity often precede the disclosure of new vulnerabilities in edge devices. The study tracked 147.8 million sessions over 103 days,…
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
The Chinese APT group known as GopherWhisper has been identified as targeting the Mongolian government using multiple cloud-based tools for espionage. Active since November 2023, the group has backdoored at least 12…
Iranian media has alleged that the United States used backdoors and botnets to disable networking equipment during the ongoing conflict, with claims that devices from Cisco, Juniper, Fortinet, and MikroTik experienced…
A tech support scam campaign has sent over 13 million emails to Japanese addresses from mid-December 2025 to May 2026. The campaign utilized workplace-themed lures to attract victims to fake security alert websites.…
The TierOne dark web forum has initiated an article contest offering a total prize pool of $10,000 for submissions focused on vulnerability exploitation. The contest runs from April 13, 2026, to May 14, 2026, with…
MikroTik is a technology platform tracked by ThreatCluster, appearing in 10 threat clusters built from 16 intelligence report mentions.
The most recent intelligence report mentioning MikroTik on ThreatCluster is dated July 25, 2026. Activity was first observed April 7, 2026, giving a tracked span from then to July 25, 2026.
Across ThreatCluster reporting, MikroTik most frequently co-occurs with Apt27, Apt28, Berserk Bear, Crouching Yeti, Dragonfly, among 12 tracked related entities.
The most significant recent cluster is “GRU Compromises Home Routers in 23 States to Steal Outlook Credentials” (6 articles · Updated May 22, 2026). MikroTik appears across 10 threat clusters in total, listed above with sources.
MikroTik appears in 16 intelligence report mentions across 10 deduplicated threat clusters, aggregated from 17,000+ monitored sources.