Russian Government-Backed Hackers Breach Multiple Home Routers and Steal Passwords

TL;DR AI
2 min readKey summary
Russian government‑backed hackers (APT28) breached multiple home routers and stole passwords.
NCSC and Lumen reported the attackers exploited vulnerabilities in MikroTik and TP‑Link models to perform man‑in‑the‑middle attacks.
APT28 changed router DNS settings to hijack requests, proxying legitimate traffic to attacker‑owned IP addresses.
Reported visible sign was only a popup about connecting to an untrusted source, while attackers could access OAuth tokens and other credentials.
From late 2025 to early 2026 over 290,000 IPs sent DNS requests; about 18,000 IPs are estimated as likely victims (medium confidence); the FBI disabled the U.S. portion and Lumen said it helped disrupt the botnet.



