Switch language한국어
Back to the list

Russian state hackers are hijacking TP-Link and MicroTik routers to steal Outlook credentials, cybersecurity center warns — APT28 group targets DNS and redirects traffic to attacker-controlled servers

TL;DR AI

Key summary

2 min read
  1. Since 2024 APT28 has been exploiting vulnerable SOHO routers to overwrite DHCP and DNS settings.

  2. The NCSC assesses APT28 is the GRU’s 85th Main Special Service Centre.

  3. The group configures VPS instances as malicious DNS resolvers and redirects downstream traffic through attacker-controlled DNS servers.

  4. Lookups for Outlook-related domains (autodiscover-s.outlook.com, imap-mail.outlook.com, outlook.live.com, outlook.office.com, outlook.office365.com) were pointed to attacker-owned IPs hosting adversary-in-the-middle infrastructure.

  5. Multiple TP-Link models (including WR841N, Archer C5/C7, WR740N, WR941ND and others) and MikroTik routers were targeted; APT28 likely used CVE-2023-50224 via an unauthenticated HTTP GET to obtain credentials.

Read the original