Russian Fancy Bear Hackers Hijack Thousands of Home Routers Globally
Image: The Times

Russian Fancy Bear Hackers Hijack Thousands of Home Routers Globally

07 April, 2026.Russia.6 sources

Key Takeaways

  • Thousands of home routers worldwide hijacked to steal credentials and manipulate traffic.
  • APT28 (Fancy Bear) linked to GRU, orchestrated these router-hijack campaigns.
  • UK NCSC reports two new APT28 campaigns targeting routers.

Scope and Methodology

The campaign targeted unpatched MikroTik and TP-Link devices using known vulnerabilities and default credentials.

Image from CyberSecurityNews
CyberSecurityNewsCyberSecurityNews

The U.K.'s NCSC confirmed spying had been carried out since 2024.

Microsoft identified at least 18,000 networks compromised globally.

Victims continued using their networks normally while attackers invisibly proxied traffic through Russian-controlled infrastructure.

Credential Theft and Espionage

Attackers redirected victim internet requests to spoof websites under their control, harvesting passwords and tokens.

The infiltration did not require installing malware on endpoints.

Image from Gadget Review
Gadget ReviewGadget Review

Discovered victims included government agencies and law enforcement.

Government Response

Court-authorized operations remotely deleted malware and blocked re-access pathways.

The campaign elevated consumer-grade hardware to a front-line battlefield of cyber espionage.

More on Russia