Russian Military Hackers Hijack Thousands of Home Routers for Global Spying
Russia's APT28 leverages tens of thousands of unpatched SOHO routers to intercept Microsoft 365 tokens and bypass MFA in a global 120-country campaign.
Russian Intelligence Exploits Home Routers in Massive Global Espionage Campaign
Russian military intelligence has launched a sprawling cyber-espionage operation, hijacking tens of thousands of consumer routers to steal login credentials and bypass multifactor authentication (MFA), researchers revealed on Tuesday.
An investigation by Lumen Technologies’ Black Lotus Labs identifies APT28—a threat group linked to the GRU, Russia’s military intelligence agency—as the architect of the campaign. The operation has successfully compromised between 18,000 and 40,000 devices across 120 countries, primarily targeting popular home and small-office (SOHO) hardware from MikroTik and TP-Link.
Old Vulnerabilities, New Sophistication
The attackers are focusing on "end-of-life" routers that no longer receive security patches. By exploiting known vulnerabilities, APT28 gains control of the devices to manipulate Domain Name System (DNS) settings.
In a technical "adversary-in-the-middle" (AitM) maneuver, the hackers redirected traffic intended for legitimate services—including Microsoft 365—to malicious servers. When unsuspecting users attempted to log in, the hackers intercepted their traffic, successfully harvesting OAuth tokens and other credentials even after users completed MFA challenges.
The attackers are focusing on "end-of-life" routers that no longer receive security patches.
“Forest Blizzard [APT28] consistently evolves its tactics to stay ahead of defenders,” Black Lotus researchers noted. They highlighted the group's ability to blend cutting-edge tools, such as the large language model (LLM) dubbed 'LAMEHUG', with "tried-and-true" hijacking techniques.
A Rapid Escalation
The operation reportedly began on a small scale in May 2025. However, activity surged in August 2025 after the UK’s National Cyber Security Center (NCSC) exposed a separate malware campaign. In response to the public exposure, APT28 pivoted immediately, ramping up the router hijacking to maintain its flow of stolen data.
Between December 12 and mid-January, researchers observed over 290,000 distinct IP addresses making requests to the malicious DNS resolvers controlled by the GRU.
How the Attack Works
- Infiltration: Attackers exploit unpatched vulnerabilities in older routers.
- Redirection: DNS settings are modified so that requests for specific authentication domains point to Russian-controlled servers.
- The Trap: When a user visits a targeted site, their browser may trigger a security warning because of an "untrusted certificate."
- The Theft: If the user clicks through the warning, the malicious server proxies the connection, allowing the GRU to capture authentication tokens in real-time.
Protecting Your Network
Security experts urge users to be proactive as APT28 has a long history of targeting consumer hardware, including the 2018 "VPNFilter" attack that affected 500,000 devices.
To secure your home or office network, specialists recommend:
- Audit DNS Settings: Check your router administration panel for any unrecognized DNS server addresses.
- Heed Browser Warnings: Never ignore or "click through" TLS/SSL certificate warnings when accessing sensitive accounts.
- Hardware Lifecycle: Replace routers that have reached "end-of-life" status and no longer receive firmware updates from the manufacturer.
- Monitor Logs: Periodically review router event logs for unauthorized configuration changes.
As of early 2026, APT28 remains one of the most persistent threats to global digital infrastructure, demonstrating that even a standard home router can become a weapon in international espionage.
