惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
量子位
MongoDB | Blog
MongoDB | Blog
N
Netflix TechBlog - Medium
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog
A
About on SuperTechFans
腾讯CDC
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
Last Week in AI
Last Week in AI
H
Help Net Security
WordPress大学
WordPress大学
博客园 - 司徒正美
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
Tailwind CSS Blog
博客园 - 【当耐特】
S
SegmentFault 最新的问题
美团技术团队
M
MIT News - Artificial intelligence
L
LangChain Blog
博客园 - 聂微东

Truesec

The Ryde Data Breach - Truesec CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223)
Russian Espionage Campaign Targets Home Routers
2026-04-15 · via Truesec

Threat Insight

The Russian GRU threat actor known as Forest Blizzard, has conducted a large-scale cyber espionage campaign by targeting small office and home office (SOHO) routers, to conduct adversary-in-the-middle attacks.

The threat actor targets unprotected routers and manipulates their DNS settings so that traffic to certain domains gets redirected to an adversary-in-the-middle (AitM) site, where credentials and tokens to the actual site can be harvested and exfiltrated, before the traffic gets routed back to the real site.

This is not the first time sophisticated threat actors have focused on routers in their cyber espionage campaigns. Truesec has previously reported how both Russian and Chinese threat actors have targeted routers.

Assessment

This campaign uses a well-known technique to harvest credentials and session tokens via an AitM site. The victim enters their credentials into a fake login page that stores the credentials and then redirects them to the real site, using the same credentials.

The novel part is that instead of using phishing links to lure the victim to visit the fraudulent site, they manipulate DNS records to direct them to the AitM site. This type of attack can be especially powerful against people working from home, with a private home router.

The attacks described appear to have primarily been directed against old MikroTik and TP-Link routers, but theoretically any router could be breached this way. Routers normally do not have nearly as much protection as computer clients and servers.

This is a reminder that not just clients, but routers and other OT devices are also increasingly targeted by threat actors.

We recommend that you review your organizational policies and guidelines governing the use and management of these types of devices, including both centrally managed corporate devices and personal devices used in home or remote environments. Assess your current capabilities to update, maintain, and secure these devices in order to reduce exposure and mitigate associated risks.

Wherever feasible, implement strong security measures such as VPN tunnels, multi-factor authentication (MFA), centralized DNS, traffic filtering, or similar controls. However, these measures may not always be practical or technically possible, and some level of risk may need to be accepted.

For further recommendations and best practices, review the list of mitigations provided by the NCSC. [2]

If you have any further questions, please do not hesitate to reach out to Truesec for support.

References

[1] https://www.lumen.com/blog-and-news/en-us/frostarmada-forest-blizzard-dns-hijacking
[2] https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations