APT28 router DNS hijacking for credential theft
Case score 56
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 56
- Main story score
- 56
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Campaign Lead campaign score from the router DNS hijacking and credential theft activity. main
Overview
Latest development Open development history FBI and DoJ neutralize APT28 router DNS hijacking network On April 7, 2026, the US Department of Justice and the FBI said they neutralized the US portion of APT28’s DNS hijacking network, which spanned more than 23 US states and used compromised SOHO routers, especially TP-Link routers, to redirect traffic through attacker-controlled DNS servers and steal credentials from targeted organizations. The FBI said it was working with ISPs to notify affected users, and court-authorized remediation steps can reset router DNS settings, remove APT28-installed resolvers, and prevent further abuse of the original access path.
-
APT28 router DNS hijacking warning
On April 7, 2026, the UK’s National Cyber Security Centre (NCSC) warned that APT28 was abusing vulnerable internet routers and compromised SOHO routers, including TP-Link WR841N devices, by changing DHCP DNS settings to actor-owned IP addresses and routing requests through attacker-controlled VPS/DNS servers. The advisory said the infrastructure linked to both campaigns had been actively modified by APT28 since 2024, and Microsoft Threat Intelligence separately said APT28 and Storm-2754 had been compromising VPS servers to exploit SOHO routers since at least August 2025. The setup enabled adversary-in-the-middle (AitM) interception of browser sessions and desktop applications to steal passwords, OAuth tokens, and other credentials from targeted organizations.