Russia's military hacks thousands of consumer routers to steal credentials

TL;DR AI
2 min readKey summary
Researchers at Lumen Technologies’ Black Lotus Labs verified an APT28 campaign compromising an estimated 18,000–40,000 consumer routers in 120 countries.
Most targeted devices were older, unpatched routers made by MikroTik and TP-Link.
Attackers exploited the compromised routers as proxies to connect to many other routers and to proxy traffic to selected domains.
The campaign manipulated DNS lookups for select websites and propagated changes to workstation-connected devices via DHCP.
The infrastructure was controlled by APT28, a GRU-linked group also known as Pawn Storm, Sofacy Group, Sednit, Tsar Team, Forest Blizzard (STRONTIUM).



