← Back to Feed
APT28 exploit routers to enable DNS hijacking operations
April 7, 2026 · NCSC UK · Severity: HIGH
Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.
Key Takeaways
- UK exposes Russian military intelligence (APT28) hijacking vulnerable routers for global cyber operations targeting governments.
- APT28 exploits unpatched router vulnerabilities to enable DNS hijacking operations against organizations worldwide.
- Organizations should patch edge devices, monitor for DNS anomalies, and implement network segmentation to counter Russian cyber operations.