Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

APT28 router DNS hijacking for credential theft

Updated 08.04.2026 13:03
Case score 56
Members 1 First seen 07.04.2026 18:30 Latest activity 08.04.2026 13:03

Overview

APT28 is using compromised **SOHO routers** and attacker-controlled DNS servers to reroute traffic, place browser and application sessions through adversary infrastructure, and steal credentials from targeted organizations. The operation changes router DNS settings, including on TP-Link devices such as the WR841N, and one model is associated with **CVE-2023-50224**. Available evidence says the infrastructure has been modified since 2024 and related compromise patterns have been visible since at least August 2025. The **NCSC** warned on April 7, 2026, and the US **FBI** and **DoJ** later said they neutralized the US portion of the network across more than 23 states while working with ISPs to reset router DNS settings and remove attacker-installed resolvers. Available evidence does not quantify the full victim set.
Latest development Open development history 1 earlier development FBI and DoJ neutralize APT28 router DNS hijacking network On April 7, 2026, the US Department of Justice and the FBI said they neutralized the US portion of APT28’s DNS hijacking network, which spanned more than 23 US states and used compromised SOHO routers, especially TP-Link routers, to redirect traffic through attacker-controlled DNS servers and steal credentials from targeted organizations. The FBI said it was working with ISPs to notify affected users, and court-authorized remediation steps can reset router DNS settings, remove APT28-installed resolvers, and prevent further abuse of the original access path.
  1. Earlier development

    APT28 router DNS hijacking warning

    On April 7, 2026, the UK’s National Cyber Security Centre (NCSC) warned that APT28 was abusing vulnerable internet routers and compromised SOHO routers, including TP-Link WR841N devices, by changing DHCP DNS settings to actor-owned IP addresses and routing requests through attacker-controlled VPS/DNS servers. The advisory said the infrastructure linked to both campaigns had been actively modified by APT28 since 2024, and Microsoft Threat Intelligence separately said APT28 and Storm-2754 had been compromising VPS servers to exploit SOHO routers since at least August 2025. The setup enabled adversary-in-the-middle (AitM) interception of browser sessions and desktop applications to steal passwords, OAuth tokens, and other credentials from targeted organizations.

Signals

Impact signals
CVEs/products
Geographic context
Status
Threat context

Threat actor context

2 listed

Tooling context

1 tools
Tools

Member happenings

Campaign APT28 SOHO router DNS hijacking and credential theft campaign
Updated 07.04.2026 18:30 Lead Contribution 56
Objective Espionage Campaign Active

**APT28** is running **two malicious campaigns** that abuse **vulnerable SOHO routers** and attacker-controlled **DNS/VPS infrastructure** to reroute traffic and steal credentials. The operation creates **AitM** risk for targeted organizations by sending browser sessions and other connections through malicious servers. The activity has been observed **since 2024** and, in related infrastructure, **since at least August 2025**.