{"id":11951,"date":"2026-04-08T10:03:40","date_gmt":"2026-04-08T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/08\/fbi-disrupts-russian-router-hijacking-operation-compromised-thousands-of-users\/"},"modified":"2026-04-08T10:03:40","modified_gmt":"2026-04-08T10:03:40","slug":"fbi-disrupts-russian-router-hijacking-operation-compromised-thousands-of-users","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/08\/fbi-disrupts-russian-router-hijacking-operation-compromised-thousands-of-users\/","title":{"rendered":"FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users"},"content":{"rendered":"<p>    FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The U.S. Justice Department and the FBI have successfully dismantled a massive cyberespionage network in a court-authorized takedown dubbed \u201cOperation Masquerade.\u201d<\/p>\n<p>Announced on April 7, 2026, the technical operation neutralized thousands of <a href=\"https:\/\/cybersecuritynews.com\/hackers-compromise-soho-routers-botnet\/\" target=\"_blank\" rel=\"noreferrer noopener\">compromised small office\/home office (SOHO) routers<\/a> that were hijacked by Russian military intelligence to spy on global targets.<\/p>\n<p>The disruption targeted a hacking unit within Russia\u2019s Main Intelligence Directorate (GRU), widely tracked by cybersecurity researchers as APT28, Fancy Bear, Forest Blizzard, and Sednit.<\/p>\n<p>Since at least 2024, these state-sponsored hackers have actively exploited known security vulnerabilities to <a href=\"https:\/\/cybersecuritynews.com\/camaro-dragon-hacker-group\/\" target=\"_blank\" rel=\"noreferrer noopener\">steal credentials for thousands of TP-Link routers worldwide.<\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"h-russian-router-hijacking-operation\"><strong>Russian Router Hijacking Operation<\/strong><\/h2>\n<p>Once the GRU actors gained unauthorized access to a router, they manipulated its <a href=\"https:\/\/cybersecuritynews.com\/zloader-dns-c2-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">Domain Name System (DNS) settings<\/a>. This effectively redirected the victim\u2019s internet traffic to malicious, attacker-controlled DNS resolvers.<\/p>\n<p>While the initial router compromises were indiscriminate, the hackers used an automated filtering system to identify high-value targets in the military, government, and critical infrastructure sectors.<\/p>\n<p>For these selected targets, the malicious DNS resolvers served fraudulent records that mimicked legitimate online services, such as <a href=\"https:\/\/cybersecuritynews.com\/microsoft-outlook-windows-bug\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Outlook Web Access.<\/a><\/p>\n<p>This allowed the GRU to execute <a href=\"https:\/\/cybersecuritynews.com\/aitm-phishing-attacks-targeting-microsoft-365\/\" target=\"_blank\" rel=\"noreferrer noopener\">Actor-in-the-Middle (AitM) attacks<\/a> against encrypted network traffic.<\/p>\n<p>By routing traffic through their servers, the attackers successfully <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-customer-authentication-tokens\/\" target=\"_blank\" rel=\"noreferrer noopener\">harvested unencrypted passwords, authentication tokens,<\/a> emails, and other sensitive data from devices connected to the compromised networks.<\/p>\n<p>To stop the espionage campaign, the FBI developed and deployed a series of remote commands to the compromised routers across 23 states.<\/p>\n<p>These commands gathered vital evidence, purged the malicious GRU DNS resolvers, and restored legitimate ISP default settings.<\/p>\n<p>The commands also locked out the attackers by <a href=\"https:\/\/cybersecuritynews.com\/apache-tika-core-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">patching the original means of unauthorized access<\/a>.<\/p>\n<p>The government extensively tested these actions alongside MIT Lincoln Laboratory to ensure they did not break normal router functionality or access private user data.<\/p>\n<p>The disruption effort was a collaborative success involving the FBI\u2019s Boston and Philadelphia Field Offices, with critical threat intelligence provided by Microsoft and Black Lotus Labs at Lumen.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-recommended-remediation-steps\"><strong>Recommended Remediation Steps<\/strong><\/h2>\n<p>While the FBI has secured the compromised devices, the agency urges all SOHO router owners to take proactive steps to defend their networks:<\/p>\n<ul class=\"wp-block-list\">\n<li>Replace any <a href=\"https:\/\/cybersecuritynews.com\/d-link-declines-to-patch-rce-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">End-of-Life (EoL)<\/a> or unsupported routers immediately.<\/li>\n<li>Upgrade the hardware to the latest available firmware from the manufacturer.<\/li>\n<li>Verify the authenticity of the DNS resolvers listed in your router\u2019s configuration settings.<\/li>\n<li>Review and update firewall rules to prevent the public exposure of remote management services.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The FBI is currently working directly with Internet Service Providers<\/a> to notify impacted users.<\/p>\n<p>If you believe your router was compromised, you are encouraged to check the official TP-Link download center for proper configuration guidelines and file a report with the FBI\u2019s Internet Crime Complaint Center (IC3).<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fbi-disrupts-russian-router-hijacking\/\">FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fbi-disrupts-russian-router-hijacking\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users The U.S. Justice Department and the FBI have successfully dismantled a massive cyberespionage network in a court-authorized takedown dubbed \u201cOperation Masquerade.\u201d Announced on April 7, 2026, the technical operation neutralized thousands of compromised small office\/home office (SOHO) routers that were hijacked by Russian military intelligence [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-11951","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11951"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11951"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11951\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11951"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}