
Russian Fancy Bear Hackers Hijack Thousands of Home Routers Globally
Key Takeaways
- Thousands of home routers worldwide hijacked to steal credentials and manipulate traffic.
- APT28 (Fancy Bear) linked to GRU, orchestrated these router-hijack campaigns.
- UK NCSC reports two new APT28 campaigns targeting routers.
Scope and Methodology
Russian government hackers hijacked thousands of home and small-office routers worldwide to redirect traffic and steal credentials.
“A large-scale campaign by Forest Blizzard, a Russian military-linked threat actor, targeting home and small-office routers to hijack DNS traffic and intercept encrypted communications with over 200 organizations and 5,000 consumer devices already compromised”
The campaign targeted unpatched MikroTik and TP-Link devices using known vulnerabilities and default credentials.

The U.K.'s NCSC confirmed spying had been carried out since 2024.
Microsoft identified at least 18,000 networks compromised globally.
Victims continued using their networks normally while attackers invisibly proxied traffic through Russian-controlled infrastructure.
Credential Theft and Espionage
Attackers redirected victim internet requests to spoof websites under their control, harvesting passwords and tokens.
The infiltration did not require installing malware on endpoints.

Discovered victims included government agencies and law enforcement.
Government Response
The DOJ, FBI, NSA, GCHQ, and international partners executed coordinated operations to neutralize the botnet.
“Russian hacking group APT28 has been exploiting vulnerable internet routers to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations, the UK government has warned”
Court-authorized operations remotely deleted malware and blocked re-access pathways.
The campaign elevated consumer-grade hardware to a front-line battlefield of cyber espionage.
More on Russia

Iran and Houthis Threaten Bab Al-Mandeb Strait Closure, Widening Iran War
15 sources compared

Ukraine Strikes Russia's Primorsk Port and NORSI Refinery, Inflicting Major Damage
20 sources compared

Russia Claims Full Control of Ukraine's Luhansk Region
11 sources compared

China Seeks Diplomatic Role in Iran War, US Shows Little Interest
54 sources compared