APT28 exploit routers to enable DNS hijacking operations
ID: f88a9b1c-0075-4e0c-a643-9a2687623c5b
STIX ID: report--f88a9b1c-0075-4e0c-a643-9a2687623c5b
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2026-04-07
Last Modified Date: 2026-04-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The UK NCSC reports that APT28 has been exploiting vulnerabilities in SOHO routers (notably TP-Link models via CVE-2023-50224 and some MikroTik devices) to overwrite DHCP/DNS settings so downstream devices use attacker-controlled DNS servers; this DNS hijacking funnels targeted Outlook and email-related requests to malicious infrastructure enabling adversary-in-the-middle operations to harvest passwords and OAuth tokens. The advisory provides cluster-based VPS/banner indicators, large lists of associated IP addresses, targeted domains, affected router models, MITRE ATT&CK mappings, and defensive mitigations.
