Policy & Regulation
Russian hackers compromise thousands of routers to steal credentials
Russian hackers have hijacked thousands of routers, affecting at least 18,000 victims across around 120 countries, according to security researchers and government agencies.
On Tuesday, security researchers and government authorities warned that Russian government hackers have hijacked thousands of home and small business routers around the world. The campaign, run by the hacking group known as Fancy Bear (also known as APT 28), is aimed at redirecting internet traffic to steal their passwords and access tokens. Fancy Bear, known for its high-profile hacks and spying operations, including the breach of the Democratic National Committee in 2016 and the destructive hack that hit satellite provider Viasat in 2022, is widely believed to be part of Russia’s intelligence agency, the GRU. According to the NCSC—the U.K. government’s cybersecurity unit—and Black Lotus Labs, the research arm of Lumen, the group targeted unpatched routers made by MikroTik and TP-Link. The hackers exploited previously disclosed vulnerabilities to compromise these devices, many of which run outdated software, allowing them to spy on users without their knowledge.
The scale of the operation spans around 120 countries, affecting at least 18,000 victims. According to Black Lotus Labs, the compromised targets include government departments, law enforcement agencies, and email providers across North Africa, Central America, and Southeast Asia. Microsoft, which also released details of the campaign, identified over 200 organizations and 5,000 consumer devices affected by the hacking operations. These affected entities include at least three government organizations in Africa. By modifying the routers’ settings, the hackers redirected victims to spoof websites to steal credentials, bypassing two-factor authentication—a security process requiring two forms of identification.
The NCSC characterized the campaign as “likely opportunistic in nature, with the actor casting a wide net to reach many potential victims, before narrowing in on targets of intelligence interest as the attack develops.” In response, government authorities have moved to disrupt the operations. The FBI is expected to announce the takedown of several domains used in the campaign, having worked with a coalition including Lumen to disrupt the botnet and take it offline. Additionally, the U.S. Justice Department announced on Tuesday afternoon that it had neutralized the compromised routers located on U.S. soil. Under court authorization, the FBI sent a series of commands to the compromised devices to collect evidence, reset settings, and prevent the hackers from regaining access.
Why it matters
This campaign highlights the vulnerability of unpatched consumer and small-business hardware as a vector for state-sponsored espionage, effectively bypassing security measures like two-factor authentication.