Back to News
research

Russian government hackers broke into thousands of home routers to steal passwords

Lorenzo Franceschi-Bicchierai
Loading...
5 min read
0 likes
⚡ Quantum Brief
Russian state hackers from the GRU-linked group Fancy Bear (APT 28) compromised 18,000+ routers across 120 countries, exploiting unpatched MikroTik and TP-Link devices to steal credentials via traffic redirection. The campaign, active for years, used known vulnerabilities to hijack routers and redirect victims to spoofed sites, bypassing two-factor authentication by capturing login tokens and passwords without detection. Targets included government agencies, law enforcement, and email providers in North Africa, Central America, and Southeast Asia, with Microsoft identifying 200+ organizations and 5,000 consumer devices affected. The U.S. Justice Department and FBI disrupted the botnet, resetting compromised U.S.-based routers via court-authorized commands to block re-entry, while a coalition including Lumen’s Black Lotus Labs took key infrastructure offline. Authorities describe the attacks as opportunistic, casting a wide net before focusing on high-value intelligence targets, continuing a pattern of aggressive cyber espionage tied to past breaches like the 2016 DNC hack.
AI Audio Summary
0:00 / 0:00
Click to play
Untitled design (20).png
Quantum News · Media Library

A group of Russian government hackers have hijacked thousands of home and small business routers around the world as part of an ongoing campaign aimed at redirecting victim’s internet traffic to steal their passwords and access tokens, security researchers and government authorities warned on Tuesday. This is the latest tactic by the long-running Russian hacking group known as Fancy Bear, or APT 28, known for its high-profile hacks and spying operations, including the breach of the Democratic National Committee in 2016 and the destructive hack that hit satellite provider Viasat in 2022. Fancy Bear is widely believed to be part of Russia’s intelligence agency GRU. The hacking group targeted unpatched routers made by MikroTik and TP-Link using previously disclosed vulnerabilities according to the U.K. government’s cybersecurity unit NCSC and Lumen’s research arm Black Lotus Labs, which released new details of the campaign Tuesday. According to the researchers, the hackers were able to spy on large numbers of people over the course of several years by compromising their routers, many of which run outdated software, leaving them vulnerable to remote attacks without their owners’ knowledge. The NCSC said that these operations are “likely opportunistic in nature, with the actor casting a wide net to reach many potential victims, before narrowing in on targets of intelligence interest as the attack develops.” Per the researchers and government advisories, the Russian hackers hacked routers to modify the device’s settings so that the victim’s internet requests are surreptitiously passed to infrastructure run by the hackers. This allows the hackers to redirect victims to spoof websites under their control, then steal passwords and tokens that let the hackers log in to that victim’s online accounts without needing their two-factor authentication codes.

Black Lotus Labs said that Fancy Bear compromised at least 18,000 victims in around 120 countries, including government departments, law enforcement agencies, and email providers across North Africa, Central America, and Southeast Asia. Techcrunch event This Week Only: Up to $482 savings for Disrupt 2026 Offer ends April 10, 11:59 p.m. PTYour next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where 10,000+ founders, investors, and tech leaders gather for three days of 250+ tactical sessions, powerful introductions, and market-defining innovation. Register now to secure these savings.

This Week Only: Up to $482 savings for Disrupt 2026 Offer ends April 10, 11:59 p.m. PTYour next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where 10,000+ founders, investors, and tech leaders gather for three days of 250+ tactical sessions, powerful introductions, and market-defining innovation. Register now to secure these savings. San Francisco, CA | October 13-15, 2026 REGISTER NOW Microsoft, which also released details of the campaign on Tuesday, said in a blog post that its researchers identified over 200 organizations and 5,000 consumer devices affected by these hacking operations, including at least three government organizations in Africa. The FBI is expected to announce the takedown of several domains used in this campaign by the hackers. Lumen said it was part of a coalition, including the FBI, that disrupted the botnet and took it offline. A spokesperson for the FBI did not respond to requests for comment prior to publication. On Tuesday afternoon, the U.S. Justice Department announced that it neutralized the compromised routers located on U.S. soil, thanks to a court authorization. The DOJ said that the FBI “developed a series of commands to send to compromised routers,” to collect evidence, reset settings, and prevent hackers from breaking back in. Updated to include information from DOJ’s announcement. Topics APT28, Black Lotus Labs, cybersecurity, espionage, hacking, Microsoft, NCSC, Routers, russia, Security Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio April 30 San Francisco, CA StrictlyVC kicks off the year in SF. Get in the room for unfiltered fireside chats with industry leaders, insider VC insights, and high-value connections that actually move the needle. Tickets are limited. REGISTER NOW Most Popular Google quietly launched an AI dictation app that works offline Ivan Mehta North Korea’s hijack of one of the web’s most used open source projects was likely weeks in the making Zack Whittaker In Japan, the robot isn’t coming for your job; it’s filling the one nobody wants Kate Park Embattled startup Delve has ‘parted ways’ with Y Combinator Anthony Ha Anthropic says Claude Code subscribers will need to pay extra for OpenClaw usage Anthony Ha Anthropic took down thousands of GitHub repos trying to yank its leaked source code — a move the company says was an accident Tim Fernholz The reputation of troubled YC startup Delve has gotten even worse Julie Bort

Read Original

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.