Cybersecurity — 2026-04-08
FBI Disrupts GRU Network of 18,000 Compromised SOHO Routers Used for DNS Hijacking and Token Theft
Microsoft, the FBI, and IC3 disclosed on April 7 that GRU-linked APT28 (
Analysis
The DNS hijacking method for token theft is a different operational approach from the Signal phishing campaign reported in prior cycles; APT28 is running parallel collection programs. The FBI's Operation Masquerade disrupted the US portion, but the global infrastructure likely extends well beyond the neutralized nodes. End-of-life routers remain an unpatched attack surface that no advisory will resolve.
The DNS hijacking method for token theft is a different operational approach from the Signal phishing campaign reported in prior cycles; APT28 is running parallel collection programs. The FBI's Operation Masquerade disrupted the US portion, but the global infrastructure likely extends well beyond the neutralized nodes. End-of-life routers remain an unpatched attack surface that no advisory will resolve.