Czech cyber-spies struck against Russian hackers. VZ described the operation against APT28
According to the published information, the attackers for several months compromised thousands of home and office routers worldwide, including devices on the territory of the Czech Republic. The compromised devices were then used as intermediaries for further operations, to mask attacks and to intercept network communication.

Aktivní zásah proti infrastruktuře GRU
České Vojenské zpravodajství has published new details about an international operation aimed at the Russian hacker group APT28, also known as Fancy Bear. The group has long been associated with the Russian military intelligence GRU and is among the most active state-backed actors in cyberespionage.
According to the published information, the attackers for several months compromised thousands of home and office routers worldwide, including devices on the territory of the Czech Republic. The compromised devices were then used as intermediaries for further operations, to mask attacks and to intercept network communication.
The operation was carried out in cooperation with the U.S. FBI and other foreign partners. The intervention itself took place in early April and, according to Vojenského zpravodajství, during it Czech specialists adjusted the configuration of part of the abused infrastructure and secured potentially exploitable devices on the territory of the Czech Republic.
Routery jako nástroj špionáže
According to the released technical details, the APT28 group exploited known vulnerabilities primarily in SOHO routers (Small Office / Home Office). In some cases the devices had outdated firmware or publicly known security flaws.
The attackers then changed DNS and network settings, allowing them to redirect traffic, capture login credentials, or hide the origin of other cyber operations.
Using compromised routers as hops is, according to security services, one of the main reasons why attribution of such attacks is complicated.
"If they attacked directly from Russia, detecting them would be significantly easier," one of the officers involved in the operation told Seznam Zprávy.
Potvrzení z USA i Británie
The information from Czech authorities is also confirmed by foreign security institutions.
The U.S. Department of Justice together with the FBI announced an operation against infrastructure used by the Russian GRU for DNS hijacking and adversary-in-the-middle attacks. The British NCSC subsequently published a technical analysis of the APT28 campaign focused on compromising network devices.
According to British experts, the attackers have long used compromised routers and other edge devices to build an anonymization layer for state-supported operations.
Jeden z mála veřejně komunikovaných aktivních zásahů
For the Czech Vojenské zpravodajství this is one of the few publicly communicated active interventions in cyberspace.
The ability to carry out active defensive operations was granted to the Czech military intelligence only after legislative changes in 2021. These changes allowed Vojenskému zpravodajství not only to monitor threats but in certain cases also to actively intervene against ongoing cyberattacks.
According to the director of the Národního centra kybernetických operací Václav Borovička, this is a fundamental change in the approach to cyber defence.
"Before, it was mainly about detection and recommendations. There was no one who could actively interfere with attackers' infrastructure in peacetime," Borovička said.
Hybridní válka bez vyhlášení konfliktu
Security experts have long warned that state-sponsored APT groups represent one of the biggest cyber threats to Europe and NATO member states.
The goal of such operations is often not immediate destruction of systems but long-term espionage, obtaining sensitive data or building access to critical infrastructure in case of future escalation of conflict.
APT28 has in the past been linked to attacks against government institutions, military organizations, diplomatic targets and election systems.
According to Vojenského zpravodajství, such operations are part of a broader trend of hybrid activities aimed at destabilizing states without the need for open military conflict.
Slabým místem zůstávají domácí routery
The case also again highlights the long-standing problem of everyday network devices. Cheap home routers often do not receive security updates, use default passwords or run for years without any management.
Such devices can serve as ideal infrastructure for state-backed attackers.
Security organizations therefore recommend regularly updating firmware, changing default passwords and disabling remote management of devices if it is not necessary.
Česko ukazuje, že umí aktivně zasáhnout
The operation against APT28 infrastructure represents one of the most visible examples of active cyber defence in the Czech environment in recent years.
Besides the technical intervention, experts say it also has an important symbolic dimension: it shows that Czech security forces are no longer only in a passive role, but can, together with foreign partners, actively disrupt state hackers' infrastructure.
At the same time, they send a clear signal that such operations in the digital space can have tangible consequences.