Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.
What happened?
Russian state-sponsored actors, identified as APT28, are actively compromising routers to manipulate DHCP and DNS settings. By hijacking these protocols, attackers redirect network traffic through servers they control.
The Attack Mechanism: Adversary-in-the-Middle (AitM)
Once DNS traffic is redirected, the actors perform AitM attacks to intercept sensitive data, including:
- Login Credentials: Usernames and passwords for web and email services.
- Authentication Tokens: OAuth tokens used to bypass traditional login screens.
- Sensitive Data: Unauthorised access to private communications and organisational files.
Targeting Strategy
These operations are primarily opportunistic. APT28 casts a wide net by targeting a broad range of vulnerable routers globally. Once initial access is gained, they “filter” through the victims to identify and prioritize targets with high intelligence or strategic value.
The National Cyber Security Centre (NCSC) has released a technical analysis of APT28 (a highly sophisticated Russian GRU intelligence unit) and their ongoing campaign to hijack DNS settings via compromised routers.
The Threat Actor: APT28
Also known as Fancy Bear or Forest Blizzard, this group is tied to the Russian GRU. They have a history of high-profile attacks, including the 2015 breach of the German Parliament and the 2018 attempt to disrupt the OPCW.
How the Attack Works (DNS Hijacking & AitM)
- Exploitation: APT28 exploits public vulnerabilities in routers (primarily SOHO models like TP-Link and MikroTik) to gain administrative access.
- DNS Manipulation: They overwrite the router’s DHCP/DNS settings to point toward malicious DNS servers they control.
- Redirection: When a user attempts to visit specific sites (like Outlook or Office 365), the malicious DNS server redirects them to a fake, actor-controlled page.
- Credential Theft: Through an Adversary-in-the-Middle (AitM) attack, the actors harvest passwords and OAuth tokens from unsuspecting users.
Key Infrastructure Clusters
- Cluster One: Modified SOHO router settings so that all connected devices (laptops, phones) inherited the malicious DNS. They specifically targeted email-related domains.
- Cluster Two: Focused on interactive operations and traffic forwarding, frequently targeting MikroTik routers located in Ukraine.
Technical Indicators of Compromise (IoCs)
Commonly Targeted TP-Link Models
- Archer Series: C5, C7
- WDR Series: 3500, 3600, 4300
- WR Series: 740N, 840N, 841N (specifically CVE-2023-50224), 941ND, 1043ND
- Access Points: WA801ND, WA901ND
High-Value Targeted Domains
If your network traffic for these domains is being rerouted, you may be a victim:
outlook.office365.comoutlook.office.comimap-mail.outlook.comautodiscover-s.outlook.com
Server Fingerprints
Look for these specific banner patterns on your network:
- Pattern 1: SSH on Port 56777 | “dnsmasq-2.85” on UDP 53
- Pattern 2: SSH on Port 35681 | “dnsmasq-2.85” on UDP 53
Mitigation Summary
The NCSC recommends that organisations and home users:
- Patch Immediately: Ensure all routers are running the latest firmware to close known vulnerabilities like CVE-2023-50224.
- Audit DNS Settings: Manually verify that your router’s DNS settings point to trusted providers (e.g., your ISP, Google 8.8.8.8, or Cloudflare 1.1.1.1).
- Monitor for AitM: Use holistic tradecraft to detect unusual redirections or certificate errors when accessing email services.
Note: The attackers use a wide “opportunistic” net before narrowing their focus on targets of high intelligence value. Even if you aren’t a primary target, your hardware could be used as a stepping stone.
What should you do?
To protect your organisation against the threats outlined in this advisory, the NCSC recommends implementing the following multi-layered defences:
1. Infrastructure & Device Security
- Secure Management Interfaces: Never expose management interfaces to the public internet. Use a “browse-down” architecture to ensure administrative tasks are performed from a secure, isolated environment.
- Vulnerability Management: Keep all devices and networks updated with the latest supported software versions. Apply security patches immediately and maintain active, updated antivirus scanning.
- Upgrade Obsolete Systems: Transition to modern platforms with built-in security features. If you must use “end-of-life” products, apply temporary mitigations to reduce the increased risk.
- Automated Updates: Ensure operating systems and productivity tools stay current. Office 365 users should utilise “Click-to-Run” for seamless application updates.
2. Advanced Technical Controls
- Application Allowlisting: Where supported, implement allowlists to ensure only authorized applications can execute, effectively blocking unauthorized or malicious software.
- Intrusion Detection: Deploy a host-based intrusion detection system (HIDS) tailored to your budget and technical requirements to monitor for suspicious activity on individual devices.
- Robust Authentication: Implement Multi-Factor Authentication (MFA) or 2-Step Verification (2SV) across all corporate services to neutralize the threat of stolen passwords.
3. Monitoring & Reporting
- Security Logging: Establish a comprehensive monitoring capability. Collecting and analyzing log data is critical for identifying and responding to network intrusions.
- Culture of Reporting: Treat employees as your primary defense. Encourage staff to report suspicious activity, ensure they feel safe doing so (never punish for accidental clicks), and investigate every report thoroughly.
More reading
https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations