Gen. partnerAlgotech

Russian APT28 abuses home routers. DNS hijacks enabled silent collection of credentials

The attack hinges on changing the DNS configuration directly on the compromised router. Once an attacker obtains administrative access, they configure the device so that all DNS queries are sent to servers under their control.

|
April 9, 2026
Russian APT28 abuses home routers. DNS hijacks enabled silent collection of credentials

Routers as an overlooked entry point

Skupina APT28 (Forest Blizzard), dlouhodobě spojovaná s ruskou vojenskou rozvědkou GRU, zneužila slabě zabezpečené SOHO routery značek MikroTik a TP-Link k vytvoření vlastní infrastruktury pro kybernetickou špionáž.

Kampaň označená jako FrostArmada běží podle zjištění bezpečnostních týmů minimálně od května 2025. Útočníci se v ní zaměřují na zařízení na okraji sítě, která bývají často špatně spravovaná a dlouhodobě neaktualizovaná.

DNS redirection as the basis of the attack

The attack hinges on changing the DNS configuration directly on the compromised router. Once an attacker obtains administrative access, they configure the device so that all DNS queries are sent to servers under their control.

When a user accesses, for example, email or a login page, the DNS response can be forged. The user is then redirected without any obvious warning to the attacker-controlled infrastructure.

An attack you can't see

A defining feature of this campaign is its stealth. Adversary-in-the-Middle (AitM) attacks occur without any required interaction from the victim. They do not require clicking a link or opening an attachment.

The attacker can capture login credentials, OAuth tokens, and other sensitive data without the user noticing any issue. Services often appear to function normally.

Tens of thousands of devices worldwide

The campaign gradually grew to global proportions. In December 2025 more than 18 000 unique IP addresses across at least 120 countries were observed communicating with the attackers' infrastructure.

Microsoft also identified over 200 affected organizations and thousands of endpoints. Targets included primarily government institutions, security agencies, and providers of email and cloud services.

Exploiting known weaknesses

In the case of TP-Link WR841N routers, the attackers, among other things, exploited vulnerability CVE-2023-50224, which allows authentication bypass and retrieval of stored credentials via specially crafted HTTP requests.

After taking control of a device, the DNS settings are changed and the attackers then select "interesting" targets. Not all traffic is actively exploited – attackers sift through large volumes of data to pick specific victims with higher intelligence value.

According to the U.S. Department of Justice, these operations were linked to unit GRU 26165.

Action against the infrastructure

Part of the infrastructure was disrupted as part of an international operation called Operation Masquerade, involving U.S. authorities and other partners.

The goal was to take offline the servers used for DNS redirection and limit the attackers' ability to conduct further operations.

Shift in tactics

According to Microsoft, this is the first observed instance of this group using DNS hijacking at scale for AitM-style attacks, including in the context of encrypted communications.

From a defense perspective the crucial change is a shift in approach. Attackers are not striking the target organization directly but the infrastructure that stands in front of it. A router thus becomes an intermediary through which traffic can be monitored long-term and credentials harvested.

The campaign shows how significant a role apparently innocuous edge devices play today. A router that remains unpatched and unchecked can easily become an entry point into an entire organization.

In this case APT28 did not rely on sophisticated malware but on a combination of known vulnerabilities and clever manipulation of network traffic. The result is an attack that is quiet, scalable, and very difficult to detect.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.