Cyber Operations — 2026-04-10

FBI Operation Masquerade Neutralizes GRU Router Botnet After UK-Led Exposure of Two-Year APT28 Espionage Campaign

The FBI Boston Field Office executed Operation Masquerade, a court-authorized operation to neutralize home and small office routers across at least 23 U.S. states compromised by GRU Military Unit 26165 (APT28/Fancy Bear). The UK National Cyber Security Centre, FBI, Microsoft, and Lumen Black Lotus Labs jointly announced that the GRU had quietly hijacked over 18,000 routers worldwide for at least two years, building a covert surveillance network exploiting TP-Link and MikroTik vulnerabilities for espionage and credential theft.

Analysis
Operation Masquerade demonstrates the FBI-NCSC-Microsoft trilateral model for disrupting state-sponsored infrastructure, a template likely to be reused. The two-year dwell time on 18,000 routers illustrates how consumer-grade network equipment remains the softest target in the espionage collection ecosystem, with no user awareness or vendor patching incentive.
1 sources
  1. Russian hacking group targets home and small office routers to spy on users - Malwarebytes

View in full brief →

UNCLASSIFIED // OPEN SOURCE