APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential Theft — Threadlinqs Intelligence
As of 2026-05-30, APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential Theft is a high-severity apt threat attributed to APT28 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0330 · Severity: HIGH · Status: MONITORING · Category: APT
Attribution: APT28 · Russia · ESPIONAGE
Russian GRU-linked APT28 (Fancy Bear / Forest Blizzard / Pawn Storm) is exploiting vulnerable internet-facing SOHO routers to hijack DNS resolution, enabling adversary-in-the-middle (AiTM)
On April 7, 2026, the UK National Cyber Security Centre (NCSC) published an advisory exposing an active campaign by Russian state cyber group APT28 that exploits vulnerable internet routers to conduct DNS hijacking operations. APT28 — attributed to Russia's GRU 85th Main Special Service Centre (GTsSS), Military Unit 26165 — compromises commonly used SOHO routers and reconfigures their DNS settings to covertly reroute victim internet traffic through attacker-controlled servers.
The DNS hijacking technique is a form of adversary-in-the-middle (AiTM) attack. By modifying DNS resolution on compromised routers, APT28 redirects users attempting to reach legitimate web and email services to malicious intermediary servers. These servers present convincing credential harvesting pages or transparently proxy traffic while extracting authentication material — including passwords, session cookies, and OAuth 2.0 access tokens — before forwarding victims to the real service. This makes the compromise invisible to end users.
The campaign follows an opportunistic targeting model: APT28 initially casts a wide net by compromising large numbers of vulnerable routers, then narrows focus to victims of intelligence interest as the operation develops. This pattern is consistent with APT28's documented tradecraft of bulk infrastructure compromise followed by selective exploitation.
This campaign builds on APT28's extensive history of router exploitation. In February 2024, the FBI disrupted the Moobot botnet — a network of hundreds of compromised Ubiquiti EdgeRouters that APT28 had been using since at least 2022 to harvest credentials, proxy network traffic, and host spearphishing landing pages. The actors accessed EdgeRouters using default credentials and deployed Trojanized OpenSSH server processes, Python credential-harvesting scripts, and custom routing rules to redirect phishing traffic. Despite the FBI takedown, APT28 has continued to target router infrastructure.
APT28's router exploitation is also linked to their exploitation of CVE-2017-6742, an SNMP remote code execution vulnerability in Cisco IOS and IOS XE routers. The NCSC and CISA jointly documented APT28 deploying the Jaguar Tooth malware to Cisco routers via this vulnerability to collect device and network information and establish backdoor access.
The DNS hijacking campaign connects to APT28's broader 2026 operational tempo. The group has been conducting parallel campaigns including: the PRISMEX malware deployment targeting NATO logistics and Eastern European government entities via CVE-2026-21509 and CVE-2026-21513; the AUTHENTIC ANTICS credential theft malware that embeds within Outlook processes to intercept Microsoft 365 credentials and OAuth tokens; credential harvesting campaigns targeting Turkish energy, European think tanks, and organizations across North Macedonia and Uzbekistan; and the BEARDSHELL/COVENANT malware campaign targeting Ukrainian military infrastructure.
The DNS hijacking operation is particularly dangerous because it operates at the network infrastructure layer, affecting all devices using the compromised router for DNS resolution. Individual endpoint security controls may not detect the compromise since traffic appears to flow normally from the endpoint perspective. Organizations and individuals relying on compromised routers for DNS resolution are exposed to credential theft across all web services accessed through that connection.
Mitigation requires securing router management interfaces, applying firmware patches, changing default credentials, implementing DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) on endpoints, deploying multi-factor authentication on all critical accounts, and monitoring for DNS configuration changes on network devices.
Weaknesses (CWE)
CWE-287, CWE-346, CWE-350, CWE-798
Target sectors: government, military, defense, energy, critical-infrastructure, transportation, logistics, diplomatic, think-tanks, technology, nuclear
Target regions: Europe, North America, Eastern Europe, United Kingdom, Ukraine, Poland, Czech Republic, Romania, Slovakia, Slovenia, Turkey, North Macedonia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2017-6742, T1190, T1566, T1557, T1110, T1528, T1187, T1557, T1114, T1546, T1505