Cybercrime
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
Cyber RTApril 9, 20263 min read

The Russia-linked APT28 group, also known as Forest Blizzard, has been exploiting insecure MikroTik and TP-Link routers since May 2025, turning them into malicious infrastructure for cyber espionage. This campaign, named FrostArmada, hijacks DNS traffic to capture credentials. A joint operation with the U.S. Department of Justice has disrupted the network. APT28 targeted government and critical infrastructure sectors globally, using DNS hijacking for espionage.
The Russia-linked threat actor APT28, also known as Forest Blizzard, has been associated with a new cyber espionage campaign targeting insecure MikroTik and TP-Link routers. This campaign, active since at least May 2025, involves modifying router settings to convert them into malicious infrastructure. The operation, codenamed FrostArmada by Lumen's Black Lotus Labs, aims to exploit vulnerable home and small office internet devices to hijack DNS traffic and collect network data passively.
The technique employed by APT28 involves altering DNS settings on compromised routers to intercept local network traffic and exfiltrate authentication credentials. When users request targeted domains, traffic is redirected to an attacker-in-the-middle (AitM) node, allowing credentials to be harvested and exfiltrated. This method enables a nearly invisible attack that requires no user interaction, making it particularly insidious.
A joint operation involving the U.S. Department of Justice, FBI, and international partners has disrupted and taken offline the infrastructure associated with this campaign. The U.S. DoJ, in a press statement, revealed that the DNS hijacking operation allowed Russian intelligence to target individuals of interest to the Kremlin, including those in military, government, and critical infrastructure sectors. This law enforcement effort has been named Operation Masquerade.
The campaign is believed to have started in a limited capacity in May 2025, with widespread exploitation and DNS redirection beginning in August. By December 2025, the operation had reached its peak, with over 18,000 unique IP addresses from more than 120 countries communicating with APT28 infrastructure. The campaign primarily targeted government agencies, law enforcement, and third-party service providers across North Africa, Central America, Southeast Asia, and Europe.
Microsoft's Threat Intelligence team attributed the activity to APT28 and its subgroup, Storm-2754. The team identified over 200 organizations and 5,000 consumer devices affected by the malicious DNS infrastructure. DNS hijacking allows nation-state actors like Forest Blizzard to maintain persistent, passive visibility and reconnaissance at scale by compromising edge devices upstream of larger targets.
The DNS hijacking activity facilitated AitM attacks, enabling the theft of passwords, OAuth tokens, and other credentials for web and email services, increasing the risk of broader organizational compromise. This marks the first time APT28 has been observed using DNS hijacking at scale to support AiTM of Transport Layer Security (TLS) connections after exploiting edge devices.
APT28 exploited TP-Link WR841N routers using an authentication bypass vulnerability (CVE-2023-50224) to extract stored credentials. The threat actors, linked to Military Unit 26165 of the GRU, have exploited known vulnerabilities to redirect DNS requests to GRU-controlled servers. An automated filtering process determined which DNS requests warranted interception, with fraudulent DNS records facilitating AitM attacks against encrypted network traffic.
A second server cluster was found to receive DNS requests via compromised routers, forwarding them to remote actor-owned servers. This cluster engaged in interactive operations targeting MikroTik routers in Ukraine. Microsoft's analysis suggests that while Forest Blizzard's DNS hijacking campaign has primarily focused on information collection, it could potentially be used for malware deployment or denial of service attacks. The campaign underscores the ongoing threat posed by sophisticated state-sponsored cyber actors.


