Home OSINT News Signals
CYBER

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

๐Ÿ•“ 1 min read

EXCLUSIVE: RUSSIAN CYBER ARMY SEIZES HOME ROUTERS IN GLOBAL INTERNET HIJACKING SCHEME

A silent, large-scale invasion is underway, and itโ€™s targeting the very device in your living room. The Russian state-backed hacking unit APT28, also tracked as Forest Blizzard, has been caught in an aggressive global campaign to seize control of millions of common home and small office routers. Since at least May 2025, this group has systematically compromised insecure models from brands like MikroTik and TP-Link, turning them into a sprawling, malicious network for espionage and data theft.

This is not a simple malware infection; it is a fundamental hijacking of the internet's plumbing. The hackers modify the routers' Domain Name System (DNS) settings, a critical function that directs your web traffic. This allows them to stealthily redirect users to fake websites designed for credential harvesting and sophisticated phishing attacks, creating a perfect storm for a massive data breach. The campaign represents a terrifying escalation, moving from targeting high-value corporate networks to weaponizing the consumer hardware that forms the backbone of global connectivity.

Cybersecurity analysts confirm the operation leverages multiple critical vulnerabilities, including suspected zero-day exploits that manufacturers had no time to patch. "They are building a shadow internet," warns one unnamed senior threat intelligence analyst. "By controlling these routers, they can intercept any unencrypted data, deploy ransomware at scale, and hide their tracks with impunity. The scale is unprecedented."

Every individual and business using a compromised router is now a potential victim. Your online banking, corporate emails, and personal communications could be flowing through servers controlled by a foreign intelligence service. This attack fundamentally undermines trust in the basic infrastructure of the web and raises severe questions about blockchain security for crypto transactions if routing nodes can be so easily subverted.

We predict this router-hijacking blueprint will be copied by other state and criminal groups within months, leading to a new wave of global cyber chaos. The age of passive hardware is over; your router is now a frontline target.

Your internet is under new management, and the landlord is in Moscow.

Telegram X LinkedIn
Back to News