logo

APT28 exploit routers to enable DNS hijacking operations

ID: f88a9b1c-0075-4e0c-a643-9a2687623c5b

STIX ID: report--f88a9b1c-0075-4e0c-a643-9a2687623c5b

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2026-04-07

Last Modified Date: 2026-04-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The UK NCSC reports that APT28 has been exploiting vulnerabilities in SOHO routers (notably TP-Link models via CVE-2023-50224 and some MikroTik devices) to overwrite DHCP/DNS settings so downstream devices use attacker-controlled DNS servers; this DNS hijacking funnels targeted Outlook and email-related requests to malicious infrastructure enabling adversary-in-the-middle operations to harvest passwords and OAuth tokens. The advisory provides cluster-based VPS/banner indicators, large lists of associated IP addresses, targeted domains, affected router models, MITRE ATT&CK mappings, and defensive mitigations.