WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Russian APT Actors Exploit Vulnerable Routers for DNS Hijacking
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partnerships
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Russian APT Actors Exploit Vulnerable Routers for DNS Hijacking

TLP:CLEAR

Author: Chase Snow

Created: Thursday, April 9, 2026 - 15:06

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: On April 7, the FBI in coordination with other federal and international partners, released a Public Service Announcement (PSA) warning that Russian General Staff Main Intelligence Directorate (GRU) cyber actors are actively exploiting vulnerable, end-of-life routers to enable persistent access and facilitate follow-on activity, including credential harvesting and network reconnaissance. Similarly, the UK’s National Cyber Security Centre reports APT28 (GRU-affiliated group) is leveraging vulnerabilities to conduct DNS hijacking operations, redirecting legitimate traffic to adversary-controlled infrastructure.

Analyst Note: Members are encouraged to review the PSA and NCSC alert for specific tactics, techniques, and affected device types, and to implement the following mitigations:

  • Identify and replace end-of-life networking equipment
  • Update to latest firmware versions
  • Change default usernames and passwords
  • Disable remote management interfaces from the internet
  • Monitor for unauthorized DNS configuration changes

Additional mitigation guidance and details are available within the referenced reports.

Original Sources:

  • https://www.ic3.gov/PSA/2026/PSA260407
  • https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations

Additional Reading:

  • (TLP:CLEAR) FBI FLASH: Cyber Criminal Services Target End-of-Life Routers to Launch Attacks and Hide Their Activities

Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 10.2, 11, 12

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar