HomeSecurityFBI Destroys APT28's DNS Hijacking Network

FBI Disrupts APT28's DNS Hijacking Network

Russian hackers APT28 continue to exploit vulnerable network devices for extensive DNS hijacking campaigns, enabling adversary-in-the-middle attacks . Recent developments indicate that these operations have prompted immediate intervention by U.S. authorities . The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a network of compromised routers controlled by APT28.

FBI DNS Hijacking APT28

According to findings that align with previous reports from the NCSC, the group exploits routers to intercept communications, collect credentials , and target individuals and organizations of interest.

DNS Hijacking and Adversary-in-the-Middle Techniques

APT28's operations include DNS hijacking, a technique that affects the way domain names are translated into IP addresses. By changing DNS settings, often at the router level, attackers redirect legitimate traffic through malicious infrastructure. This enables adversary-in-the-middle attacks, where victims are unknowingly connected to fake services.

See also: Iranian Hackers Target US Critical Infrastructure with PLC Attacks

These malicious endpoints are designed to mimic legitimate platforms, allowing attackers to intercept login sessions and extract sensitive data, such as passwords, OAuth tokens, and emails.

Both the FBI and NCSC have noted that these attacks can affect browser sessions and desktop applications, increasing the scale and effectiveness of credential collection.

US Targets APT28 Infrastructure

The operation, disclosed by the Department of Justice, targeted a network of SOHO routers compromised by APT28, also known as Fancy Bear, Sofacy, Sednit, STRONTIUM, Forest Blizzard and Pawn Storm. The group has been linked to Unit 26165 of Russia’s GRU. Since at least 2024, APT28 actors have exploited known vulnerabilities to gain access to thousands of TP-Link routers worldwide.

After stealing credentials, the attackers modified the router settings to redirect DNS traffic to malicious servers under their control.

Initially, these operations were generalized. However, later, attackers implemented automated filtering mechanisms to identify DNS queries with intelligence value. For selected targets, malicious DNS resolvers returned spoofed records for domains, particularly those that mimicked Microsoft Outlook services, to facilitate adversary-in-the-middle attacks against encrypted traffic.

FBI Disrupts APT28's DNS Hijacking Network

Through this approach, APT28 was able to collect unencrypted passwords, authentication tokens, emails, and other sensitive data from devices connected to compromised routers.

See also: APT28 exploits SOHO routers in DNS Hijacking campaign

Official Statements on the Threat

US officials have described the campaign as persistent and dangerous. Assistant Attorney General John A. Eisenberg said: “The GRU’s use of networks of American homes and businesses remains a serious and persistent threat.”

US Attorney David Metcalf added: “ Russian military intelligence has again compromised American hardware to obtain critical data ,” stressing that the government will continue to respond aggressively to state-sponsored cyberthreats

FBI officials also highlighted the scale of the campaign. Assistant Director Brett Leatherman noted that the compromised routers were used worldwide for espionage , while Special Agent Ted E. Docks emphasized that devices in more than 23 U.S. states had been used as weapons.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How the FBI Disrupted the DNS Hijacking Network

As part of the court-mandated operation, referred to as Operation Masquerade, the FBI deployed technical measures to neutralize the American portion of APT28's infrastructure. According to court documents:

  • The FBI sent commands to compromised routers to collect evidence of APT28 activity.
  • Reset DNS settings, removing malicious resolvers and restoring legitimate ISP settings.
  • It eliminated the ability of perpetrators to regain unauthorized access.

The operation was carefully tested on affected TP-Link devices to ensure that it would not disrupt normal functionality or collect user content. The recovery steps can be reversed by users through a factory reset or manual configuration changes.

See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment

Targeted Services and Indicators

APT28's DNS hijacking campaigns have often targeted domains related to Microsoft Outlook, including:

  • autodiscover-s.outlook[.]com
  • imap-mail.outlook[.]com
  • outlook.live[.]com
  • outlook.office[.]com
  • outlook.office365[.]com

These targets reflect a clear focus on email intelligence gathering. The supporting infrastructure includes numerous malicious IP ranges and recognizable server configurations, such as unusual SSH ports and “dnsmasq-2.85” DNS services.

FBI Disrupts APT28's DNS Hijacking Network

Security Recommendations

Both the FBI and NCSC recommend immediate steps to reduce the risks associated with DNS hijacking and adversary-in-the-middle attacks:

  • Replace hardware that is no longer supported
  • Update the firmware to the latest available versions
  • Verify DNS settings to ensure they point to legitimate resolvers
  • Disable or secure remote management interfaces
  • Implement firewall rules to limit exposure
  • Enable multi-factor authentication (MFA)
  • Monitor your networks and report suspicious signs to the relevant authorities.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS