惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threat Research - Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
V
Vulnerabilities – Threatpost
GbyAI
GbyAI
P
Proofpoint News Feed
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog
A
About on SuperTechFans
T
Tenable Blog
M
MIT News - Artificial intelligence
IT之家
IT之家
I
Intezer
D
DataBreaches.Net
爱范儿
爱范儿
T
Threatpost
C
CERT Recently Published Vulnerability Notes
云风的 BLOG
云风的 BLOG
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
K
Kaspersky official blog
大猫的无限游戏
大猫的无限游戏
A
Arctic Wolf
Y
Y Combinator Blog
Cyberwarzone
Cyberwarzone
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
Spread Privacy
Spread Privacy
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
AWS News Blog
AWS News Blog
博客园 - 聂微东
C
Check Point Blog
S
Securelist
有赞技术团队
有赞技术团队
雷峰网
雷峰网
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
D
Docker
G
GRAHAM CLULEY
T
The Exploit Database - CXSecurity.com
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tailwind CSS Blog
L
Lohrmann on Cybersecurity
G
Google Developers Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
L
LangChain Blog

Cyber Security News

BugHunter - Bug Bounty Toolkit Powered by Claude and Free AI Providers Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications Facebook and Instagram Down Globally, Users Reporting Multiple Issues Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers Critical Langflow Vulnerability Exploited to Execute Malicious Code Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems Hackers Abuse Residential Proxy Networks to Hide Malicious Activity and Evade Detection Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability Oracle Emergency Security Update to Fix Critical RCE Vulnerability GreatXML BitLocker Bypass 0-Day Exploited Via Windows Defender Offline Scan Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script Hackers Abuse AWS CloudTrail and Google Cloud Logging to Evade Detection and Exfiltrate Logs China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks Top 5 Best Tools for Simulated DDoS Attacks in 2026 Critical Vulnerability in Hugging Face Transformers Enables Remote Code Execution Attacks OWASP CVE Lite CLI - New Tool to Scan for Vulnerabilities in Your Projects Anthropic's Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated] Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware New Magecart Attack Turns Stripe into a Malware Command Server Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks
Tushar Subhra Dutta · 2026-06-13 · via Cyber Security News

One of the most persistent hacking groups in the world has found a new way to stay hidden.

The threat actor known as Fancy Bear, formally tracked as APT28 and attributed to Russia’s military intelligence unit GRU Unit 26165, has been quietly shifting how it runs cyberattack operations.

Instead of relying on traditional infrastructure, the group now hijacks home routers and consumer devices to build a shadow network nearly impossible to trace.

For over two decades, APT28 has targeted government bodies, defense organizations, diplomatic missions, and critical infrastructure, focusing heavily on NATO member states and Ukraine.

The group operates under more than 30 known aliases, including Forest Blizzard, Sofacy, Pawn Storm, and Sednit. What makes its latest campaign especially alarming is how invisible it has become, with attack traffic blending into normal internet activity.

Analysts from Sekoia, who have been tracking APT28 for several years, identified a significant structural shift in how the group manages its attack infrastructure.

Sekoia said in a report shared with Cyber Security News (CSN) that APT28 moved large portions of its operations onto compromised SOHO routers and edge devices, replacing rented virtual private servers it previously used as command centers.

The scale of this infrastructure is striking. At its peak in December 2025, researchers observed more than 18,000 unique IP addresses across 120 countries communicating with APT28-controlled servers.

Timeline (Source - Sekoia)
Timeline (Source – Sekoia)

Around 200 organizations and 5,000 consumer devices were affected, with victims coming primarily from foreign ministries, law enforcement agencies, and IT hosting providers.

APT28’s tradecraft has also evolved sharply. The group shifted from a stable malware framework to deploying short-lived, single-purpose tools discarded the moment they are exposed.

It also experimented with an AI-driven infostealer called LameHug, which queries a live AI model to generate attack commands on the fly.

This blend of disposable tools, cloud abuse, and router hijacking makes APT28 one of the most capable threat actors active today.

Fancy Bear Hackers Abuse EdgeRouters and Cloud Services

The most significant tactical shift is APT28’s takeover of consumer-grade routers. The group repurposed a criminal botnet built with the MooBot malware, seizing control of hundreds of Ubiquiti EdgeRouters in April 2022.

The botnet served three purposes: relaying stolen authentication hashes toward Microsoft Exchange, hosting phishing pages on residential IP addresses, and running custom Python scripts on the hijacked routers.

The FBI’s Operation Dying Ember dismantled this network in 2024. Even after the takedown, more than 350 datacenter servers were still calling back to attacker infrastructure, showing just how hard this kind of botnet is to fully uproot.

In 2026, APT28 broadened the same approach with a campaign called FrostArmada, this time targeting MikroTik and TP-Link routers. The attackers rewrote DNS settings to redirect traffic through their own controlled servers.

Every device on affected networks would unknowingly funnel its login requests through APT28 nodes, enabling silent theft of credentials and OAuth tokens for services like Microsoft 365.

Cloud Services as a Covert Command Channel

Beyond router hijacking, APT28 routes malware communications through legitimate cloud platforms to avoid detection.

In Operation Phantom Net Voxel, the group deployed a custom C++ backdoor called BeardShell, which uses a cloud storage API as its command channel. To anyone monitoring the traffic, it looks like a connection to a trusted cloud service.

The group can swap cloud providers easily. Researchers observed the same attack chain reused with a different file-hosting platform months later, confirming that rotating the cloud backend is now routine.

A keylogger called Slimagent, found on the same operator infrastructure, was linked to direct code lineage from X-Agent, APT28’s signature implant used over a decade ago.

To reduce exposure, organizations should keep router firmware updated, change default credentials, and disable unused remote management features.

Enterprises using cloud services should enforce phishing-resistant multi-factor authentication and regularly audit OAuth token permissions.

The FBI’s Internet Crime Complaint Center published a public alert urging home users and small businesses to review router settings after FrostArmada was disclosed.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.