Monday, August 31, 2026
LIVETop 10 International Tech News Today: AI, Chips, Apple, Cybersecurity and Startups///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Top 10 International Tech News Today: AI, Chips, Apple, Cybersecurity and Startups///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
TechnologyAI-assisted

Russian Military Hackers Hijack Thousands of Home Routers for Global Spying

Russia's APT28 leverages tens of thousands of unpatched SOHO routers to intercept Microsoft 365 tokens and bypass MFA in a global 120-country campaign.

Russian Military Hackers Hijack Thousands of Home Routers for Global Spying

Russian Intelligence Exploits Home Routers in Massive Global Espionage Campaign

Russian military intelligence has launched a sprawling cyber-espionage operation, hijacking tens of thousands of consumer routers to steal login credentials and bypass multifactor authentication (MFA), researchers revealed on Tuesday.

An investigation by Lumen Technologies’ Black Lotus Labs identifies APT28—a threat group linked to the GRU, Russia’s military intelligence agency—as the architect of the campaign. The operation has successfully compromised between 18,000 and 40,000 devices across 120 countries, primarily targeting popular home and small-office (SOHO) hardware from MikroTik and TP-Link.

Old Vulnerabilities, New Sophistication

The attackers are focusing on "end-of-life" routers that no longer receive security patches. By exploiting known vulnerabilities, APT28 gains control of the devices to manipulate Domain Name System (DNS) settings.

In a technical "adversary-in-the-middle" (AitM) maneuver, the hackers redirected traffic intended for legitimate services—including Microsoft 365—to malicious servers. When unsuspecting users attempted to log in, the hackers intercepted their traffic, successfully harvesting OAuth tokens and other credentials even after users completed MFA challenges.

The attackers are focusing on "end-of-life" routers that no longer receive security patches.
Zoé Vaillant · The Hacking Post

“Forest Blizzard [APT28] consistently evolves its tactics to stay ahead of defenders,” Black Lotus researchers noted. They highlighted the group's ability to blend cutting-edge tools, such as the large language model (LLM) dubbed 'LAMEHUG', with "tried-and-true" hijacking techniques.

A Rapid Escalation

The operation reportedly began on a small scale in May 2025. However, activity surged in August 2025 after the UK’s National Cyber Security Center (NCSC) exposed a separate malware campaign. In response to the public exposure, APT28 pivoted immediately, ramping up the router hijacking to maintain its flow of stolen data.

Between December 12 and mid-January, researchers observed over 290,000 distinct IP addresses making requests to the malicious DNS resolvers controlled by the GRU.

Advertisement

How the Attack Works

  1. Infiltration: Attackers exploit unpatched vulnerabilities in older routers.
  2. Redirection: DNS settings are modified so that requests for specific authentication domains point to Russian-controlled servers.
  3. The Trap: When a user visits a targeted site, their browser may trigger a security warning because of an "untrusted certificate."
  4. The Theft: If the user clicks through the warning, the malicious server proxies the connection, allowing the GRU to capture authentication tokens in real-time.

Protecting Your Network

Security experts urge users to be proactive as APT28 has a long history of targeting consumer hardware, including the 2018 "VPNFilter" attack that affected 500,000 devices.

To secure your home or office network, specialists recommend:

  • Audit DNS Settings: Check your router administration panel for any unrecognized DNS server addresses.
  • Heed Browser Warnings: Never ignore or "click through" TLS/SSL certificate warnings when accessing sensitive accounts.
  • Hardware Lifecycle: Replace routers that have reached "end-of-life" status and no longer receive firmware updates from the manufacturer.
  • Monitor Logs: Periodically review router event logs for unauthorized configuration changes.

As of early 2026, APT28 remains one of the most persistent threats to global digital infrastructure, demonstrating that even a standard home router can become a weapon in international espionage.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories