If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.

Most credential theft depends on a mistake. Someone clicks a link they should not have, or types their details into a site they did not check carefully enough. The router campaign run by the Russian state group APT28 needed none of that. People typed the correct web address for a service they used every day, and still handed their password to an attacker.

It is a useful case to understand, because it defeats the advice most organisations give their staff. “Check the address bar” does not help when the address is right and the destination is wrong.

What happened

Since 2024, a unit of Russian military intelligence tracked as APT28, also known as Fancy Bear and Forest Blizzard, has been compromising consumer and small-office routers and quietly changing their DNS settings. DNS is the part of the network that turns a web address you type into the address of the server you actually reach. Change it at the router, and you decide where “the correct address” leads for every device on that network.

By 2026 the campaign had reached thousands of routers, with unpatched TP-Link models among the confirmed targets. In April 2026, US and UK authorities, alongside partners from more than a dozen countries, disrupted the network. Microsoft confirmed that more than 200 organisations and around 5,000 consumer devices had been affected.

What made these routers vulnerable

The devices APT28 exploited had three things in common, and none of them were exotic. They were consumer-grade models, the kind bought off the shelf rather than specified by an IT team. Many had reached end of life, meaning the manufacturer had stopped issuing security updates, so a known flaw stayed open with no patch ever coming. And a number were still running default or weak administrator credentials, or had remote management exposed to the internet.

None of that is unusual. It describes a large share of the routers in the homes, rentals and small offices that staff connect through every day. The attackers did not need a sophisticated new exploit. They needed devices that were old, unpatched and forgotten, and there is no shortage of those.

Why it worked

Once APT28 controlled a router’s DNS, every device connecting through it, laptops, phones and tablets, inherited the change automatically. When someone opened a login page they used routinely, the tampered DNS could send them to a convincing copy instead, one that captured the password and session token they entered before passing them on. The fake pages carried valid security certificates, so the browser raised no obvious alarm.

There was no malicious link to spot and no attachment to open. The technique is not tied to any single provider, either. Because it operates on DNS, it can be pointed at any web login the attacker chooses. The person on the other end did everything they had been told to do.

Why endpoint and identity tools didn’t catch it

This is the uncomfortable part for a well-defended organisation. The redirection happened at the router, before traffic reached the laptop, so the endpoint security software on that laptop had nothing to flag. From its point of view, the user simply visited a website. Identity and multi-factor systems fared little better, because the attacker was harvesting live credentials and session tokens at the moment of entry, which can be enough to step past some protections.

The tools were not faulty. They were watching the wrong layer. The compromise sat underneath them, in a device none of them could see.

The part that matters for organisations

The routers being exploited were not enterprise equipment inside a managed office. They were the ordinary devices in homes and small offices, exactly where staff now connect to corporate systems. An organisation has no visibility of those devices, cannot patch them, and in most cases does not even know which of its people are behind a vulnerable one.

This is the uncontrolled network edge in a single example: the security of sensitive access resting on infrastructure the organisation cannot see, verify or control. Government agencies including the NSA, CISA, GCHQ and the FBI have all named unmanaged edge devices as a priority risk for exactly this reason.

How to tell if you were exposed

The practical checks are straightforward: confirm the router is not using DNS servers you do not recognise, that its firmware is current, that it is not an end-of-life model, that default credentials have been changed, and that remote management is not exposed to the internet. Certificate warnings in a browser or email client should be treated as a possible sign of redirection rather than dismissed.

We have set out the full checklist in a separate post: How to check whether your organisation is exposed to the APT28 router campaign. For an unsupported device, the honest answer is usually to replace it, because the underlying flaw will not be patched.

How Loxada addresses this

Loxada Secure replaces that unmanaged connection with a managed router running Loxada’s own firmware, not the manufacturer’s. DNS is handled by Loxada rather than left to whatever the local router happened to be set, or misconfigured, to use, so a hijacked local resolver is not in the path. The firmware is maintained and updated centrally rather than depending on the device owner or the original vendor, which removes the end-of-life problem that made these routers exploitable in the first place. Traffic is routed through Loxada’s secure connectivity layer, so the network edge your people work from is known and controlled wherever they are.

Loxada does not replace endpoint or identity tools, and it is not a monitoring product. What it removes is the specific gap this campaign exploited: an unmanaged, unpatched router quietly deciding where your people’s traffic goes.

Common questions

Who is APT28? APT28 is a cyber-espionage group attributed to Russian military intelligence, the GRU’s 85th Main Special Service Centre (Military Unit 26165). It is also known as Fancy Bear, Forest Blizzard, Sofacy and Strontium, and has been active since at least 2004, with a long record of targeting governments, defence organisations and critical infrastructure.

What is DNS hijacking? DNS is the system that translates a web address into the numerical address of a server. DNS hijacking changes that translation so a correct address resolves to a server the attacker controls. Done at the router, it affects every device on that network at once.

Does a factory reset fix it? Resetting the router, or restoring its correct DNS settings, removes the malicious configuration. But if the device is unpatched or end of life, the original weakness remains and it can be compromised again. The durable fix is to update the firmware, or replace hardware that is no longer supported.

Would a VPN have stopped it? A VPN protects traffic in transit, but it does not repair a compromised router, and depending on how it is configured, DNS resolution can still happen on the local network before or outside the tunnel. The more complete answer is to control the network edge itself, so DNS and firmware are managed rather than left to an unknown local device.

Sources: US FBI (IC3) and UK NCSC advisories, April 2026; Microsoft Threat Intelligence. APT28 is attributed to Russia’s GRU military intelligence.

If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.