惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
B
Blog RSS Feed
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Help Net Security
MyScale Blog
MyScale Blog
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
Martin Fowler
Martin Fowler
Vercel News
Vercel News
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
Last Week in AI
Last Week in AI
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
云风的 BLOG
云风的 BLOG

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns Eight in 10 UK Manufacturers Hit by Cyber Incident in a Year
Russian APT28 Hackers Hijack Routers to Steal Credentials...
Kevin Poireault · 2026-04-07 · via www.infosecurity-magazine.com

Russian hacking group APT28 has been exploiting vulnerable internet routers to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations, the UK government has warned.

In a new advisory published on April 7, the UK’s National Cyber Security Centre (NCSC) said it detected two new malicious campaigns it attributed to APT28.

Both campaigns are linked to a list of virtual private servers (VPS), which have been actively modified by APT28 since 2024 to operate as malicious domain name system (DNS) servers.

“These VPSs typically receive high volumes of DNS requests originating from routers that had been exploited by the actor likely utilising public vulnerabilities,” the NCSC advisory noted.

The NCSC assessed that the initial DNS hijacking operations are “opportunistic in nature,” meaning that the APT28 hackers likely use this method to first gain visibility of a large pool of candidates and then filter down users at each stage in the exploitation chain to triage for “victims of likely intelligence value.”

The UK government associates APT28 “almost certainly” to the Russian General Staff Main Intelligence Directorate’s (GRU) 85th Main Special Service Centre (GTsSS) Military Intelligence Unit 26165, is known under many other names, including Fancy Bear, Forest Blizzard, Strontium, the Sednit Gang, and Sofacy.

In a separate report, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025."

First Activity Cluster Targets TP-Link Routers

In the first activity cluster identified by the British cybersecurity agency, the dynamic host configuration protocol (DHCP) DNS settings of compromised SOHO routers, mostly TP-Link routers, were modified to include actor-owned IP addresses.

One of the router models appearing in this campaign, the TP-Link WR841N, was likely exploited using CVE-2023-50224, a vulnerability that enables an unauthenticated attacker to obtain information such as password credentials via specially crafted HTTP GET requests.

These settings were subsequently inherited by downstream devices, for example laptops and phones, leading requests matching APT28’s targeting criteria to be resolved by the malicious DNS servers to IP addresses owned by the threat actor.

The APT28 hackers would then attempt to conduct adversary-in-the-middle (AitM) attacks against follow-on connections, including user browser sessions and desktop applications, likely to harvest passwords, OAuth tokens and other credentials for web and email related services.

“Subsequent malicious logins using this stolen data may originate from further infrastructure not listed in this advisory,” the UK agency noted.

DNS hijacking through router compromise. Source: Microsoft Threat Intelligence
DNS hijacking through router compromise. Source: Microsoft Threat Intelligence

Read more: US – FCC Bans Foreign-Made Routers Over National Security Concerns

Second Activity Cluster Targets MikroTik and TP-Link Routers

In a second activity cluster, the NCSC observed a subset of servers receiving DNS requests via likely compromised devices including models of MikroTik and TP-Link routers.

In this campaign, the DNS requests were forwarded from these servers to further remote actor-owned servers.

This cluster of infrastructure was also involved in interactive operations against a small number of MikroTik routers, often located in Ukraine, that were likely of intelligence value to the actor.

Speaking to Infosecurity, a TP-Link spokesperson said the devices referenced in the reporting "reached End of Service and Life (EOSL) status several years ago" and  are therefore "outside of our standard maintenance lifecycle."

However, the company said it has "developed security updates for select legacy models where technically feasible. To ensure these updates take place, we recommend following the advice listed on the security advisory."

"We encourage customers using legacy or EOSL devices to upgrade to currently supported hardware that receives regular security updates. As immediate precautions, users should update to the latest available firmware, disable remote management, use strong and unique administrator passwords and restrict device access to trusted internal networks only.," the TP-Link spokesperson added.

NCSC Recommendations to Stop APT28’s Credential Theft

The NCSC provided a list of mitigation measures that could help in defending against the activity described in the advisory. These include:

  • Using browse-down architecture to prevent attackers easily gaining privileged access to your most vital assets
  • Using the latest supported versions, applying security updates promptly, deploying antivirus and regularly scanning to detect known malware threats
  • Adding applications to an allowlist
  • Deploying a host-based intrusion detection system
  • Using multifactor authentication (MFA)

The NCSC has previously attributed activity to APT28, including the 2015 cyber-attacks against the German parliament and an attempted attack against the Organisation for the Prohibition of Chemical Weapons (OPCW) in April 2018.

This article was updated on April 9 to add comments from TP-Link.