The UK’s National Cyber Security Centre (NCSC) has published a new advisory revealing that Russian cyber actors have compromised commonly used routers, allowing them to covertly reroute users’ internet traffic through malicious servers under their control.
The NCSC warned that Russian-backed cyber group APT28, linked to the infamous GRU intelligence service, is exploiting weak internet routers to run Domain Name System (DNS) hijacking operations, allowing hackers to intercept traffic and steal login credentials, including passwords and access tokens, from personal web and email services.
In a DNS hijacking attack, malicious actors redirect user queries by manipulating device settings, compromising routers, or rerouting traffic at the network level so that typing a familiar website address leads to a malicious IP, silently redirecting victims to pages designed for phishing attacks, identity theft, and malware deployment.
According to the NCSC, APT28 (aka Forest Blizzard, Fancy Bear, STRONTIUM, the Sednit Gang and Sofacy) has been running its DNS hijacking operation for at least two years, renting Virtual Private Servers (VPSs) and setting them up to function as their own DNS servers.
These servers receive large volumes of DNS requests from vulnerable home and office routers that the group has compromised, likely by exploiting publicly known vulnerabilities, and once inside, the hackers manipulate the router’s settings so all DNS requests are placed via their malicious servers.   Â
The NCSC’s advisory notes that this activity is likely opportunistic in nature, with the threat group casting a wide net to snare as many victims as possible, before narrowing in on targets of intelligence interest as the attack develops.
Organisations and network defenders are encouraged to follow the mitigation advice to effectively protect against DNS hijacking attacks, including protecting the management interfaces of systems, ensuring devices and software are maintained and up-to-date, and setting up two-step verification.
Recommended reading
- Microsoft: Russian Hackers Targeting UK Critical Industries
- Advanced Attack Drones For Ukraine in New UK Gov Deal
- New UK Sanctions Target Russian Cyber-crime Network
“This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors,” said Paul Chichester, NCSC director of operations.
“We strongly encourage organisations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice.
“The NCSC will continue to expose Russian malicious cyber activity and provide practical guidance to help protect UK networks.”
APT28 has previously been linked by the UK intelligence services to Russia’s GRU 85th Main Special Service Centre, with the NCSC having previously issued warnings about the group’s development of the AUTHENTIC ANTICS malware, and its targeting of western logistics firms and tech companies.





