Cyber Operations — 2026-04-11
FBI Disrupts GRU Router Espionage Network in Operation Masquerade, 18,000 Devices Compromised
FBI disrupted a GRU cyberespionage campaign that compromised 18,000+ TP-Link routers worldwide in Operation Masquerade, coordinated with NSA and 15 allied intelligence agencies. GRU's 85th Main Special Service Center (APT28) modified router DNS settings to intercept encrypted traffic including passwords, authentication tokens, and emails via
Analysis
Operation Masquerade represents the FBI's fourth disruption of GRU cyber infrastructure since 2018 (VPNFilter, Cyclops Blink, 2024 botnet, now DNS hijacking). The 15-nation allied coalition in the announcement reflects an expanding Five Eyes-plus cyber attribution model. The DNS hijacking technique targeting SSL/TLS-protected traffic undermines the encryption that most users assume protects their communications.
Operation Masquerade represents the FBI's fourth disruption of GRU cyber infrastructure since 2018 (VPNFilter, Cyclops Blink, 2024 botnet, now DNS hijacking). The 15-nation allied coalition in the announcement reflects an expanding Five Eyes-plus cyber attribution model. The DNS hijacking technique targeting SSL/TLS-protected traffic undermines the encryption that most users assume protects their communications.