惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
博客园 - 聂微东
有赞技术团队
有赞技术团队
The Cloudflare Blog
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
T
The Blog of Author Tim Ferriss
D
Docker
L
LangChain Blog
Vercel News
Vercel News
C
Check Point Blog
博客园 - Franky
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
V2EX
人人都是产品经理
人人都是产品经理

The Register - Security

Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw ShinyHunters claims dump puts 119K Vimeo emails in the wild
Russia's Fancy Bear still attacking routers to boost fake...
2026-04-08 · via The Register - Security

The UK's National Cyber Security Centre (NCSC) has issued a fresh warning about Russia's ongoing targeting of routers to steal passwords and other secrets.

It said APT28, aka Fancy Bear, a group widely attributed to Russian intelligence (GRU), is exploiting vulnerabilities in small and home office (SOHO) routers and changing their DNS server settings to redirect victims to websites it controls.

In many cases, altering these DNS settings can also cause downstream devices to inherit them, such as laptops and smartphones, exposing them to malicious connections.

Fancy Bear typically reroutes victims searching for commonly visited services such as Outlook to websites under its control. Victims are instead served an Outlook copycat page, into which they unwittingly enter their legitimate credentials to access the service.

TP-Link routers were name-dropped specifically, although Cisco routers were previously caught up in the same activity, which the NCSC has monitored since 2021.

A separate cluster of similar activity targeted MikroTik routers. The NCSC believes many of these were located in Ukraine, and compromising them would allow Russia to gather data with military intelligence value.

Although the DNS hijacking activity has been ongoing for years and was carried out by sophisticated threat actors, the NCSC said it was likely opportunistic rather than singling out high-value individuals for targeting.

Paul Chichester, director of operations at the NCSC, said: "This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors.

"We strongly encourage organizations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice.

"The NCSC will continue to expose Russian malicious cyber activity and provide practical guidance to help protect UK networks."

Microsoft also published its own report on the attacks, adding that APT28 (Forest Blizzard in Redmond nomenclature) was likely hoping to compromise routers at organizations upstream of large targets.

In doing so, that could give the group access to enterprise environments and a trove of other sensitive data.

It stated: "Microsoft Threat Intelligence has identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard's malicious DNS infrastructure; telemetry did not indicate compromise of Microsoft-owned assets or services."

Microsoft went on to say that APT28 could also use successful attacks for other purposes, such as DDoS attacks and deploying malware.

One of the NCSC's earlier advisories, dated April 2023, noted that similar attacks on Cisco routers resulted in APT28 deploying Jaguar Tooth malware, establishing backdoors for follow-on attacks. ®