← Back to Feed

APT28 exploit routers to enable DNS hijacking operations

April 7, 2026 · NCSC UK · Severity: HIGH

Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.

Key Takeaways

  • UK exposes Russian military intelligence (APT28) hijacking vulnerable routers for global cyber operations targeting governments.
  • APT28 exploits unpatched router vulnerabilities to enable DNS hijacking operations against organizations worldwide.
  • Organizations should patch edge devices, monitor for DNS anomalies, and implement network segmentation to counter Russian cyber operations.
☕ Buy a Coffee