News: 1775581325

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns

(2026/04/07)


The UK's National Cyber Security Centre (NCSC) has issued a fresh warning about Russia's ongoing targeting of routers to steal passwords and other secrets.

It said APT28, aka Fancy Bear, a group widely attributed to Russian intelligence (GRU), is exploiting vulnerabilities in small and home office (SOHO) routers and changing their DNS server settings to redirect victims to websites it controls.

In many cases, altering these DNS settings can also cause downstream devices to inherit them, such as laptops and smartphones, exposing them to malicious connections.

[1]

Fancy Bear typically reroutes victims searching for commonly visited services such as Outlook to websites under its control. Victims are instead served an Outlook copycat page, into which they unwittingly enter their legitimate credentials to access the service.

[2]

[3]

TP-Link [4]routers were [5]name-dropped specifically, although Cisco routers were previously caught up in the same activity, which the NCSC has monitored since 2021.

A separate cluster of similar activity targeted [6]MikroTik routers. The NCSC believes many of these were located in Ukraine, and compromising them would allow Russia to gather data with military intelligence value.

[7]

Although the DNS hijacking activity has been ongoing for years and was carried out by sophisticated threat actors, the NCSC said it was likely opportunistic rather than singling out high-value individuals for targeting.

Paul Chichester, director of operations at the NCSC, said: "This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors.

"We strongly encourage organizations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice.

[8]UK fines Irish Apple outpost over sanctions-busting payments to Russian dev

[9]Russian initial access broker who fed ransomware crews gets 81 months in US prison

[10]Russian cybercrims phish their way into officials' Signal and WhatsApp accounts

[11]Ex-L3Harris exec jailed 7 years for selling exploits to Russia

"The NCSC will continue to expose Russian malicious cyber activity and provide practical guidance to help protect UK networks."

Microsoft also published its own [12]report on the attacks , adding that APT28 (Forest Blizzard in Redmond nomenclature) was likely hoping to compromise routers at organizations upstream of large targets.

[13]

In doing so, that could give the group access to enterprise environments and a trove of other sensitive data.

It stated: "Microsoft Threat Intelligence has identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard's malicious DNS infrastructure; telemetry did not indicate compromise of Microsoft-owned assets or services."

Microsoft went on to say that APT28 could also use successful attacks for other purposes, such as DDoS attacks and deploying malware.

One of the NCSC's earlier advisories, dated April 2023, noted that similar attacks on Cisco routers resulted in APT28 deploying [14]Jaguar Tooth malware , establishing backdoors for follow-on attacks. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2adV-hL1mV3x-VWXJSu2pwgAAAJE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44adV-hL1mV3x-VWXJSu2pwgAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33adV-hL1mV3x-VWXJSu2pwgAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2025/09/08/infosec_in_brief/

[5] https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations

[6] https://www.theregister.com/2018/09/04/mikrotik_routers_pwned/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44adV-hL1mV3x-VWXJSu2pwgAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2026/03/30/apple_fine_russia_sanctions/

[9] https://www.theregister.com/2026/03/24/russian_iab_sentenced/

[10] https://www.theregister.com/2026/03/09/dutch_spies_say_russian_cybercrims/

[11] https://www.theregister.com/2026/02/25/former_l3harris_exec_jailed/

[12] https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33adV-hL1mV3x-VWXJSu2pwgAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2023/04/18/uk_us_apt28_cisco_routers/

[15] https://whitepapers.theregister.com/



Freebie

elsergiovolador

here is free password for the Fanny Boar:

hunter2

Who will save us from those no good Commie baskets /s

Anonymous Coward

Who will save us from those no good Commie baskets /s

A bunch of Polish scientists decided to flee their repressive government by
hijacking an airliner and forcing the pilot to fly them to the West. They
drove to the airport, forced their way on board a large passenger jet, and
found there was no pilot on board. Terrified, they listened as the sirens
got louder. Finally, one of the scientists suggested that since he was an
experimentalist, he would try to fly the aircraft.
He sat down at the controls and tried to figure them out. The sirens
got louder and louder. Armed men surrounded the jet. The would be pilot's
friends cried out, "Please, please take off now!!! Hurry!!!"
The experimentalist calmly replied, "Have patience. I'm just a simple
pole in a complex plane."