Cyber Operations — 2026-04-11

FBI Disrupts GRU Router Espionage Network in Operation Masquerade, 18,000 Devices Compromised

FBI disrupted a GRU cyberespionage campaign that compromised 18,000+ TP-Link routers worldwide in Operation Masquerade, coordinated with NSA and 15 allied intelligence agencies. GRU's 85th Main Special Service Center (APT28) modified router DNS settings to intercept encrypted traffic including passwords, authentication tokens, and emails via adversary-in-the-middle attacks. FBI Cyber Division Assistant Director Brett Leatherman said the attack was virtually invisible to end users because it exploited router tools rather than deploying malware. This is the FBI's fourth takedown of GRU cyber infrastructure since 2018.

Analysis
Operation Masquerade represents the FBI's fourth disruption of GRU cyber infrastructure since 2018 (VPNFilter, Cyclops Blink, 2024 botnet, now DNS hijacking). The 15-nation allied coalition in the announcement reflects an expanding Five Eyes-plus cyber attribution model. The DNS hijacking technique targeting SSL/TLS-protected traffic undermines the encryption that most users assume protects their communications.
2 sources
  1. Inside the FBI's router takedown that cut off APT28's tremendous access - CyberScoop
  2. Russia's GRU exploits vulnerable routers to steal sensitive data, Western intelligence warns - Decode39

View in full brief →

UNCLASSIFIED // OPEN SOURCE