Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

APT28 router DNS hijacking for credential theft

Updated 08.04.2026 13:03
Case score 56
Case score 56 Members 1 Latest activity 08.04.2026 13:03
Members 1 First seen 07.04.2026 18:30 Last seen 07.04.2026 18:30 Updated 08.04.2026 13:03

Overview

APT28 is using compromised **SOHO routers** and attacker-controlled DNS servers to reroute traffic, place browser and application sessions through adversary infrastructure, and steal credentials from targeted organizations. The operation changes router DNS settings, including on TP-Link devices such as the WR841N, and one model is associated with **CVE-2023-50224**. Available evidence says the infrastructure has been modified since 2024 and related compromise patterns have been visible since at least August 2025. The **NCSC** warned on April 7, 2026, and the US **FBI** and **DoJ** later said they neutralized the US portion of the network across more than 23 states while working with ISPs to reset router DNS settings and remove attacker-installed resolvers. Available evidence does not quantify the full victim set.

Signals

3 derived
Impact signals
Affected credentials from targeted organizations
CVEs/products
CVE
Status
Campaign status Active
Threat context
Actor APT28

Malware context

0 families · 1 tools
Tools
Storm-2754

Member happenings

1 related
Campaign APT28 SOHO router DNS hijacking and credential theft campaign
Updated 07.04.2026 18:30 Lead Contribution 56
Objective Espionage Campaign Active

**APT28** is running **two malicious campaigns** that abuse **vulnerable SOHO routers** and attacker-controlled **DNS/VPS infrastructure** to reroute traffic and steal credentials. The operation creates **AitM** risk for targeted organizations by sending browser sessions and other connections through malicious servers. The activity has been observed **since 2024** and, in related infrastructure, **since at least August 2025**.