Aug 17, 2026
When most people think about cybersecurity, they think about passwords, antivirus software, or suspicious emails, not the router sitting in the corner. But routers connect every device in a home or small office to the internet, and when they are outdated, unpatched, or poorly secured, they can become attractive targets for attackers.
A recently disclosed cyber espionage campaign shows why that matters. Researchers uncovered a large operation involving compromised routers and other network-edge devices across more than 120 countries, with activity linked to APT28, a Russian state-sponsored group associated with the GRU. The campaign used compromised devices to redirect traffic, support espionage, and potentially steal credentials, turning ordinary home and small-business equipment into part of a much larger attack infrastructure.
What Happened in the Russian Router Campaign?
Researchers at Lumen’s Black Lotus Labs tracked the campaign as FrostArmada and observed activity involving routers and other edge devices from manufacturers including MikroTik and TP-Link. U.S. authorities also reported that Russian GRU actors had exploited known vulnerabilities to gain access to thousands of TP-Link routers worldwide since at least 2024.
The attackers did not necessarily target each router because of who owned it. Many devices appear to have been compromised opportunistically because they were exposed to the internet, running outdated firmware, or affected by known vulnerabilities. Once compromised, those routers could be used to hide malicious traffic, redirect network connections, and serve as steppingstones toward higher-value targets.
The operation had a significant international footprint. Between December 12, 2025, and January 13, 2026, Black Lotus Labs observed more than 290,000 distinct IP addresses making at least one DNS request to infrastructure tied to the campaign. Researchers classified roughly 40,000 IPs as low-confidence potential victims and about 18,000 as moderate-confidence potential victims based on repeated interactions, so those figures should not be treated as confirmed compromised-router counts.
The broader goal appears to have been espionage rather than simple disruption. Researchers observed activity connected to government agencies, law enforcement, telecommunications, IT providers, and other organizations with intelligence value. In many cases, the compromised router may not have been the ultimate target, but part of the infrastructure used to reach, observe, or disguise activity against someone else.
Who Is APT28, and Why Target Home Routers?
APT28 is a Russian state-sponsored hacking group also known as Forest Blizzard, Fancy Bear, Sofacy, Pawn Storm, Sednit, and STRONTIUM. The group has been linked to Russia’s GRU military intelligence service and is known for cyber espionage operations targeting government, military, critical infrastructure, telecommunications, and technology organizations. In the router campaign, the goal was not simply to disrupt internet access or make money. Compromised routers gave the group infrastructure it could use to conceal activity, redirect traffic, and support intelligence-gathering operations.
Home and small-business routers are especially attractive targets because they are often overlooked after installation. Several factors make them useful to sophisticated attackers:
- They may go years without updates. Many owners rarely check router firmware after setup, leaving known vulnerabilities unpatched for long periods.
- Older devices can fall out of support. Once a manufacturer stops issuing security updates, newly discovered flaws may remain permanently exposed.
- Attackers can reuse known vulnerabilities. Instead of developing costly new exploits, threat actors can target devices that are still vulnerable to flaws for which fixes already exist.
- Routers sit at a powerful point in the network. Because they direct traffic for every connected device, a compromised router can help redirect users, alter network settings, or support surveillance without infecting each laptop or phone individually.
- They can help disguise malicious activity. A hijacked router can act as a relay or proxy, making attacker traffic appear to come from an ordinary residential or small-business internet connection.
In many cases, the owner of the router may not even be the attacker’s ultimate target. The device can instead become a steppingstone toward a higher-value organization or account, which is one reason forgotten network equipment can become such a useful tool in a broader espionage campaign.
How the Attack Worked: From Router to Stolen Credentials
The campaign relied on a chain of relatively simple techniques. Rather than infecting every laptop or phone individually, the attackers compromised routers and used their control over network traffic to create opportunities for credential theft and espionage.
- Attackers found and exploited vulnerable routers. APT28 targeted internet-facing routers and other edge devices with known vulnerabilities, outdated firmware, or exposed management interfaces. Researchers observed activity involving MikroTik and TP-Link equipment, while government advisories documented exploitation of multiple TP-Link models. The broader issue was not one specific brand, but older or poorly maintained network hardware that remained vulnerable to known flaws.
- They changed the router’s DNS settings. DNS acts like the internet’s address book, telling devices where to go when someone enters a website or service name. After compromising a router, the attackers could change its DNS settings so traffic was sent through DNS servers they controlled. This gave them the ability to selectively redirect users while allowing most normal internet traffic to continue as expected.
- The bad settings could spread to every device on the network. Routers commonly use DHCP to automatically provide network settings to connected laptops, phones, tablets, and other devices. By changing DNS at the router level, attackers could cause multiple devices to inherit the malicious settings without compromising each one individually.
- Selected traffic could be redirected through attacker-controlled infrastructure. When a user tried to reach a service of interest, the malicious DNS server could send that connection somewhere other than its intended destination. Researchers observed this technique being used in adversary-in-the-middle attacks, where attacker-controlled infrastructure was placed between the victim and a legitimate service.
- Victims could be tricked into handing over credentials or session data. In some cases, users would see a browser warning about an invalid or untrusted security certificate. If they ignored the warning and continued, attackers could potentially capture passwords, authentication tokens, email content, or other sensitive information. That is why unexpected certificate warnings should never be treated as routine pop-ups to click through.
The effectiveness of the attack came from how quietly it could operate. A compromised router might continue providing internet access normally, leaving users with little indication that their traffic was being manipulated behind the scenes.
Why This Matters to Small Businesses and Remote Workers
For small businesses, the router sitting in an office or in an employee’s home can be part of the company’s cybersecurity perimeter. Remote and hybrid workers routinely use home networks to access email, cloud platforms, file-sharing tools, and other business systems, even though the routers supporting those connections may not be monitored or maintained by the company’s IT team.
That creates a potential blind spot. A business may have strong endpoint protection, multi-factor authentication, and secure cloud applications, but an outdated or compromised router can still create opportunities for attackers to redirect traffic or intercept sensitive information. Microsoft specifically warned that unmanaged home and small-office networking devices can put business accounts and cloud access at risk even when the organization’s core systems remain secure.
The lesson for small businesses is simple: routers, firewalls, and wireless access points should be treated as managed security assets, not set-it-and-forget-it equipment. Keeping firmware current, replacing unsupported hardware, securing administrative access, and accounting for remote-work environments can help close a gap attackers are increasingly willing to exploit.
How to Protect Your Routers and Network Infrastructure
Routers should be managed with the same level of attention as other security-critical technology. Whether the device sits in a main office, branch location, home office, or remote employee’s workspace, outdated firmware and weak configurations can create unnecessary exposure.
1. Keep Firmware and Security Updates Current
Check router and firewall firmware regularly and install security updates as they become available. These updates often address known vulnerabilities that attackers can exploit long after a fix has been released. Where supported, enable automatic updates or use centralized management tools to keep business networking equipment current. Organizations with multiple locations should also establish a consistent patching process rather than relying on individual users or offices to manage updates themselves.
2. Replace Unsupported or End-of-Life Hardware
A router can continue working long after the manufacturer stops supporting it, but that does not mean it is still secure. Once a device reaches end-of-life, the manufacturer may stop releasing patches even when new vulnerabilities are discovered. Businesses should maintain an inventory of routers, firewalls, and access points and track the support status of each device. Replacement cycles should be planned before equipment becomes obsolete rather than after a security issue appears.
3. Secure Administrative Access
Businesses should use strong, unique passwords for routers, firewalls, and access points rather than reusing credentials across multiple devices. Multi-factor authentication should also be enabled where the platform supports it. Administrative access should be limited to authorized personnel and, where possible, restricted to specific management networks or approved devices. Organizations should periodically review who has administrative privileges and remove access that is no longer needed.
4. Disable Unnecessary Remote Management
Many routers allow administrators to manage the device remotely over the internet, but that feature can create additional risk if it is not properly secured. If remote administration is not required, it should be disabled. When remote management is necessary, businesses should restrict access to trusted users, networks, or IP addresses whenever possible. Secure methods such as a VPN or other controlled remote-access solution should be used instead of exposing the management interface directly to the public internet. Businesses should also verify that old or unused remote-management features have not remained enabled from a previous configuration.
5. Verify DNS Settings
Because DNS manipulation played a central role in the APT28 campaign, businesses should periodically verify which DNS servers their routers are configured to use. Those addresses should match the organization’s approved DNS provider, internet service provider, or another service that was intentionally selected. Unfamiliar DNS entries should be investigated rather than assumed to be legitimate. Administrators should also document approved settings so unexpected changes are easier to identify during future reviews.
6. Monitor Logs and Configuration Changes
Businesses should review available logs for unexpected administrative logins, configuration changes, repeated authentication attempts, or firmware activity that was not initiated by an authorized user. Configuration backups can also make it easier to identify what changed and restore a known-good setup if a device is compromised. Organizations with multiple offices or devices should consider centralized logging and network monitoring rather than reviewing each device separately. Alerts for high-risk events, such as changes to DNS settings or administrator accounts, can help security teams respond faster.
7. Do Not Ignore Certificate Warnings
Employees should be trained to take unexpected browser or application certificate warnings seriously. These warnings can indicate that a device is not communicating securely with the website or service it intended to reach. In an attack involving DNS hijacking or traffic redirection, a certificate warning may be one of the few visible signs that something is wrong. Users should avoid clicking through the warning simply to continue to the page, especially when accessing email, cloud platforms, financial systems, or other sensitive services. Instead, they should stop and report the issue to their IT or security team for investigation.
8. Include Remote Workers in Network Security Policies
Employees may be accessing sensitive business systems through routers that are several years old, poorly configured, or no longer supported by the manufacturer. Businesses should establish minimum security expectations for remote networking equipment, including firmware updates, strong passwords, and supported hardware. IT teams can also provide employees with guidance on how to check router settings and recognize when a device may need to be replaced. For higher-risk roles, organizations may want to provide approved networking equipment or other managed access solutions.
How Do You Know if Your Router Has Been Compromised?
A compromised router does not always produce obvious symptoms. In many cases, internet access may continue working normally while attackers quietly change settings or redirect selected traffic. That makes routine monitoring and configuration reviews especially important for businesses.
Potential warning signs include:
- Unfamiliar DNS servers
- Unexpected changes to router settings
- Administrator passwords that no longer work
- Logins from unknown users or locations
Repeated certificate warnings on websites or cloud applications that normally load without issue can also be a red flag, especially if multiple users on the same network experience them. Administrators should also look for unexplained firmware changes, unusual remote-access activity, or configuration updates that were not made by authorized staff.
None of these signs prove that APT28 or any specific threat actor has compromised the device. They do, however, warrant investigation. If a business suspects a router or firewall has been altered, the safest approach is to involve its IT or security team, review the device configuration and logs, update or replace unsupported hardware, and reset credentials as appropriate.
Frequently Asked Questions About Router Hacks
Can a compromised router steal passwords?
A compromised router can help attackers redirect traffic and create conditions for credential theft. In this campaign, attackers used DNS hijacking and adversary-in-the-middle techniques that could potentially expose passwords, authentication tokens, and other sensitive information when users were redirected through attacker-controlled infrastructure.
Is rebooting a router enough to fix a compromise?
Not necessarily. Rebooting may interrupt some malicious activity, but it does not address the underlying vulnerability, configuration change, or unsupported hardware that allowed the compromise to occur. Businesses should update firmware, verify DNS and administrative settings, reset credentials where appropriate, and replace equipment that is no longer supported.
Should businesses be concerned about employees’ home routers?
Yes, especially when remote employees use home networks to access sensitive business systems. A company may secure its laptops and cloud applications while still having limited visibility into the routers employees rely on every day. Businesses should include remote networking equipment in their broader security policies and provide guidance on updates, supported hardware, and secure configurations.
Protect All the Devices in Your Network with Blade Technologies
The Russian router campaign is a reminder that cybersecurity is not limited to laptops, servers, and cloud applications. Routers, firewalls, access points, and other devices running quietly in the background are also part of the security perimeter, and they can become useful tools for attackers when they are outdated, misconfigured, or forgotten.
For businesses, the takeaway is to know what equipment you have, keep it supported and patched, monitor it for unexpected changes, and replace hardware before it becomes a long-term security liability. The same principle applies to remote-work environments, where employee networks may connect directly to business-critical systems.
Blade Technologies helps businesses identify weaknesses across their technology environment, including network infrastructure, access controls, and other potential security gaps. If you are unsure whether aging hardware, outdated configurations, or unmanaged devices are creating unnecessary risk, a cybersecurity or network assessment can help uncover issues before they become larger problems. Contact our experts today to discuss how you can strengthen your cybersecurity.
Strengthen Your Cybersecurity