Just in:
Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Trump rejects munitions fears as Iran clashes resume // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // LatAm gushers and possible Venezuela exit a nightmare for Opec // Schnabel urges programmable central bank money on-chain // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // What Shein’s $27bn IPO means for Mubadala // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Adobe widens Saudi AI access with $4 billion programme // Putin holds talks with Pezeshkian in Bishkek // Qatar economy contracts 7% as energy output slumps // India plans own orbital space outpost, second after China // Apple raises evidence-destruction claims against OpenAI // Dubai hotel provides free public co-working space //

FBI cuts off APT28 router trap

U. S. authorities have dismantled the domestic arm of a cyber-espionage network that officials say was run by APT28, the Russian military intelligence hacking group also known as Fancy Bear and Forest Blizzard, after it hijacked vulnerable internet routers to redirect traffic, steal credentials and sift victims for higher-value targets. The Justice Department said the FBI used a court-authorised technical operation to identify compromised routers on U. S. soil, collect evidence, sever the hackers’ access and restore the devices to normal operation.

The operation, announced on April 7, was aimed at infrastructure linked to GRU Military Unit 26165, a unit long associated with espionage and political cyber operations in Europe and the United States. Officials said the routers had been turned into part of a malicious Domain Name System hijacking network, allowing the operators to manipulate how web traffic was routed and to position themselves between users and trusted online services. That, in turn, created an opening to capture passwords, authentication tokens, emails and other sensitive information.

What made the campaign notable was its scale and its use of ordinary small-office and home-office equipment rather than headline-grabbing attacks on large corporate systems. The Justice Department said the actors exploited known vulnerabilities to compromise thousands of TP-Link routers worldwide, while British and U. S. government alerts also pointed to MikroTik devices and other edge hardware as part of the wider abuse. Security agencies said the activity was indiscriminate at the outset, with a broad pool of devices compromised first and selected victims filtered later on the basis of intelligence value.

According to the official account, the hackers altered router settings so DNS requests were sent to servers under their control. In many cases, the altered infrastructure quietly passed queries onward, allowing the operators to observe traffic patterns and map networks without alerting the user. For selected targets, however, the operation shifted from passive surveillance to active interception. Fraudulent DNS responses steered victims towards infrastructure mimicking legitimate services, including Microsoft Outlook Web Access, enabling what cyber specialists describe as adversary-in-the-middle attacks.

Microsoft said it had identified more than 200 organisations and 5,000 consumer devices affected by the malicious DNS infrastructure, adding that the campaign touched government, information technology, telecommunications and energy networks. The company said this was the first time it had observed Forest Blizzard using DNS hijacking at scale to support adversary-in-the-middle attacks against Transport Layer Security connections after exploiting edge devices. It also said there was no sign that Microsoft-owned assets or services themselves had been compromised.

Further detail from Lumen Technologies’ Black Lotus Labs suggested the campaign had been evolving for months. Lumen said the earliest activity it tracked began in May 2025 and that the operation broadened sharply in the second half of last year, peaking in December with more than 18,000 moderate-confidence victim IP addresses from at least 120 countries communicating with the actor’s infrastructure. It said many of the apparent targets were foreign ministries, law-enforcement bodies, third-party email providers and other state-linked or strategically relevant entities across North Africa, Central America, Southeast Asia and Europe.

The international dimension was underlined by coordinated warnings from Britain and Germany. Britain’s National Cyber Security Centre said the operation exploited routers to overwrite DHCP and DNS settings, exposing organisations to credential theft, data manipulation and broader compromise. Germany’s domestic intelligence agency said several dozen affected devices had been identified there and tied the campaign to APT28’s continuing espionage activity against state, political and infrastructure targets. Reuters reported that the U. S. takedown involved partners in 15 countries, showing how law enforcement and private-sector threat researchers are increasingly working together against state-linked cyber campaigns.

For governments and businesses, the case is another reminder that cyber risk often sits at the network edge, especially in home-working and hybrid environments where unmanaged routers can become a weak point. U. S. and British officials urged users to change default credentials, disable remote management from the open internet, update firmware and replace end-of-support devices. They also warned users to treat certificate warnings seriously, since the success of interception attacks can depend on a victim clicking through an invalid security prompt.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Schnabel urges programmable central bank money on-chain // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Putin holds talks with Pezeshkian in Bishkek // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // India plans own orbital space outpost, second after China // Chinese researchers engineer self-contracting muscle grafts // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // What Shein’s $27bn IPO means for Mubadala // Adobe widens Saudi AI access with $4 billion programme // Apple raises evidence-destruction claims against OpenAI // Jordan downs eight missiles as Iran targets US bases // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // Alpha Dhabi lifts MICAD commitment to $1 billion // Russia brings cryptocurrency market law into force // Venezuela defends sovereignty after Trump oil control claim // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment //