#apt28 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #apt28, aggregated by home.social.
-
📰 Russian APT28 Hijacks Routers in DNS Poisoning Campaign
Russian APT group Forest Blizzard (APT28) is behind the 'FrostArmada' campaign, hijacking routers in hotels to steal Microsoft credentials via DNS poisoning. The attack targets users on hospitality Wi-Fi. #APT28 #CyberEspionage #DNS
🌐 cyber[.]netsecops[.]io
-
Russische Angreifer: #Microsoft365-Zugangsklau durch Hotel-Router | Security https://www.heise.de/news/Russische-Angreifer-Microsoft-365-Zugangsklau-durch-Hotel-Router-11378714.html #phishing #CyberCrime #DNS #VPN #DNSPoising #Russia 🇷🇺 #Russland 🇷🇺 #APT28 #FancyBear #ForestBlizzard #FrostArmada
-
Russische Angreifer: #Microsoft365-Zugangsklau durch Hotel-Router | Security https://www.heise.de/news/Russische-Angreifer-Microsoft-365-Zugangsklau-durch-Hotel-Router-11378714.html #phishing #CyberCrime #DNS #VPN #DNSPoising #Russia 🇷🇺 #Russland 🇷🇺 #APT28 #FancyBear #ForestBlizzard #FrostArmada
-
We all know the APT numbers for #FancyBear and #CozyBear — #APT28 and #APT29. Both are attributed to Russian #intelligence. #APT1 through 27 are all from #China. Only the #EquationGroup doesn’t have an official APT number? Wake up, you sleeping sheep—we’re being thoroughly taken for a ride here. The Equation Group—run by the #NSA or #CIA — is probably the most dangerous group in the world, and yet it’s the one that doesn’t appear under any number on the #APT list? Who are you trying to fool here when it comes to #cybersecurity?
see: attack.mitre.org/groups/index.…
#news #conspiracy #snowden #surveillance #spy #usa #russia #thread #danger #warning #fail #security #cybersecurity #internet #online #hack #hacker #software #exploit #cyberattack #cybercrime #world #worldorder #censorship #deepstate
-
APT28, an evolution of tradecraft
#APT28
https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/ -
APT28, an evolution of tradecraft
#APT28
https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/ -
Hörempfehlung.
They Talk Tech – mit Eckert und @evawolfangel Teure KI und Schwachstellen-Hype - mit Cybersicherheitsforscherin Haya Schulmann
🕸️ https://frauen-technik.podigee.io/82-new-episode
My 2ct:
Toller Beitrag! Etwas fragwürdig imo der Versuch #Stuxnet zu legitimieren: Stuxnet war genauso Verstoß gegen Hacker-Ethik wie #APT28-Angriffe. Mir fehlen Hinweise auf "friendly Cyber-Sabotage" und moralische Scheuklappen - gerade bei Despoten wie #Trump, #Thiel & #Musk. LLMs & 0Days sind imho Teil digitaler #Geopolitik
-
Hörempfehlung.
They Talk Tech – mit Eckert und @evawolfangel Teure KI und Schwachstellen-Hype - mit Cybersicherheitsforscherin Haya Schulmann
🕸️ https://frauen-technik.podigee.io/82-new-episode
My 2ct:
Toller Beitrag! Etwas fragwürdig imo der Versuch #Stuxnet zu legitimieren: Stuxnet war genauso Verstoß gegen Hacker-Ethik wie #APT28-Angriffe. Mir fehlen Hinweise auf "friendly Cyber-Sabotage" und moralische Scheuklappen - gerade bei Despoten wie #Trump, #Thiel & #Musk. LLMs & 0Days sind imho Teil digitaler #Geopolitik
-
A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202
#CVE_2026_32202 #APT28 #CVE_2026_21510
https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202 -
A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202
#CVE_2026_32202 #APT28 #CVE_2026_21510
https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202 -
Alerta en Windows: Un parche incompleto permite ataques «Zero-Click»
Una falla en la actualización de seguridad de Microsoft ha dejado una puerta abierta para que hackers vinculados a Rusia ejecuten ataques sin necesidad de interacción del usuario, poniendo en riesgo datos sensibles en toda Europa (Fuente Akamai).
La seguridad de Windows se enfrenta a una crisis de confianza tras el descubrimiento de un parche defectuoso. Según un informe de Akamai, una corrección lanzada inicialmente en febrero para mitigar una vulnerabilidad en SmartScreen resultó ser insuficiente. Este parche incompleto ha dado lugar a una nueva vulnerabilidad crítica (identificada como CVE-2026-32202), que permite ataques del tipo «Zero-Click» (sin clics). En estos ataques, el simple hecho de que un usuario visualice una carpeta que contenga un archivo malicioso permite al atacante forzar una autenticación automática con su servidor, robando las credenciales del usuario sin que este se dé cuenta.
El grupo de ciberespionaje ruso APT28 (también conocido como Fancy Bear) ha sido identificado como el principal explotador de esta brecha. Los investigadores señalan que el grupo ha estado utilizando archivos de acceso directo (.lnk) modificados para saltarse las protecciones de Windows y ejecutar código remoto. Al aprovechar el mecanismo de procesamiento de iconos de Windows Explorer, los atacantes logran que el sistema de la víctima envíe su «hash» de autenticación NTLM a un servidor remoto, lo que facilita el robo de identidad y el movimiento lateral dentro de redes corporativas y gubernamentales, especialmente en Ucrania y países de la Unión Europea.
Microsoft ha incluido una nueva corrección para este fallo específico en su tanda de parches de abril de 2026. Sin embargo, la persistencia de estas brechas subraya la complejidad de parchear sistemas heredados como Windows Shell y el framework MSHTML. Los expertos en ciberseguridad recomiendan encarecidamente a las organizaciones aplicar las últimas actualizaciones de forma inmediata y considerar la desactivación de protocolos de autenticación antiguos como NTLM en entornos sensibles para prevenir este tipo de «coerción de autenticación» que la IA y los grupos estatales están empezando a explotar con mayor frecuencia.
#akamai #apt28 #ciberseguridad #PORTADA #zeroClick -
From APT28 to RePythonNET: automating .NET malware analysis
#APT28
https://blog.sekoia.io/apt28-to-repythonnet-automating-net-malware-analysis/ -
From APT28 to RePythonNET: automating .NET malware analysis
#APT28
https://blog.sekoia.io/apt28-to-repythonnet-automating-net-malware-analysis/ -
APT28 campaign exposed 🚨
• 280+ inboxes compromised
• Ukraine + NATO targets
• 2-year espionage op -
Im eigenen Interesse:
https://freifunk-stuttgart.de/2026/04/13/hack-von-tp-link-und-mikrotik-geraeten/Ein kurzer Blogeintrag von mir.
-
Im eigenen Interesse:
https://freifunk-stuttgart.de/2026/04/13/hack-von-tp-link-und-mikrotik-geraeten/Ein kurzer Blogeintrag von mir.
-
FBI Disrupts APT28's Router-Based Espionage Operations
The FBI recently disrupted a sneaky espionage operation run by APT28, a Russian GRU-linked group notorious for its broad reach, by cutting off their access to a network of routers they used as a launching pad for further attacks. This bold move effectively severed the group's tremendous access, putting a stop to their clever tactics.
-
Військова розвідка ЧР прийняла участь у операції в рамках кібервійни з росією, разом з колегами з #США та інших країн.
Operation Masquerade проводилась в березні 2026 року і полягала у відновленні роутерів, хакнутих російськими хакерами з групи #APT28. Ця група, відома також під назвою #FancyBear, працює на російське #ГРУ, протягом 2025 року взяла під контроль тисячі роутерів #TPLink, які містили незалатані діри, і використовувала їх для перехоплення трафіку користувачів.
#hackers #cybersecurity -
Russische APT28 knacken SOHO-Router (MikroTik/TP-Link), ändern DNS für AiTM auf MS Office – Tokens geklaut ohne Malware. Über 18k Geräte betroffen. Alte Router updaten oder entsorgen! Lumen-BlackLotus-Report: https://www.lumen.com/blog-and-news/en-us/frostarmada-forest-blizzard-dns-hijacking Bleibt dran. #infosec #APT28 #RouterSec
-
APT28 Targets Ukraine, NATO Allies with PRISMEX Malware
Russian threat actor APT28 has launched a new campaign, deploying a previously unknown malware suite called PRISMEX to target Ukraine and its NATO allies, using clever concealment techniques to evade detection. This sophisticated attack combines steganography, COM hijacking, and legitimate cloud services to stay under the radar.
-
So sicherst du deinen TP-Link-Router gegen APT28-Angriffe ab
https://techupdate.io/hardware/so-sicherst-du-deinen-tp-link-router-gegen-apt28-angriffe-ab/51099/
#technews #cybersecurity #infrastruktur #tplink #apt28 #itsicherheit
-
Nevím úplně přesně, jak to číst:
‚Zresetujeme zařízení.‘ Čeští zpravodajci ve spolupráci s FBI zasáhli proti zneužitým přístrojům"‚Podstatou operace, na níž se Vojenské zpravodajství podílelo formou aktivního zásahu, bylo odebrat přístup útočníkům ke zranitelným zařízením a následně je zabezpečit, (...),‘ přibližuje Pejšek."
Znamená to, že Vojenské zpravodajství leze lidem do routerů a dělá jim úpravy ve firmwaru?
-
Nevím úplně přesně, jak to číst:
‚Zresetujeme zařízení.‘ Čeští zpravodajci ve spolupráci s FBI zasáhli proti zneužitým přístrojům"‚Podstatou operace, na níž se Vojenské zpravodajství podílelo formou aktivního zásahu, bylo odebrat přístup útočníkům ke zranitelným zařízením a následně je zabezpečit, (...),‘ přibližuje Pejšek."
Znamená to, že Vojenské zpravodajství leze lidem do routerů a dělá jim úpravy ve firmwaru?
-
Altes Problem, neue Kritikalität: Seit gestern warnt das Bundesamt für Verfassungsschutz (#BfV) vor gezielten Cyberangriffen der russischen Gruppe #APT28, die dem Militärgeheimdienst #GRU zugeordnet wird.
Auch wenn die Warnung aktuell ist, ist der Fall aus Sicht der #Cybersicherheit eigentlich nicht neu: Öffentlich auffindbare, veraltete Netzwerkgeräte werden schon seit geraumer Zeit systematisch als Einfallstor für nachrichtendienstliche Operationen genutzt:
-
Altes Problem, neue Kritikalität: Seit gestern warnt das Bundesamt für Verfassungsschutz (#BfV) vor gezielten Cyberangriffen der russischen Gruppe #APT28, die dem Militärgeheimdienst #GRU zugeordnet wird.
Auch wenn die Warnung aktuell ist, ist der Fall aus Sicht der #Cybersicherheit eigentlich nicht neu: Öffentlich auffindbare, veraltete Netzwerkgeräte werden schon seit geraumer Zeit systematisch als Einfallstor für nachrichtendienstliche Operationen genutzt:
-
FBI Disrupts Russian Hacker Network with DNS Hijacking Takedown
In a major cyber takedown, the FBI has successfully disrupted a Russian hacker network by pulling the plug on compromised US-based routers, effectively cutting off the threat actor's malicious infrastructure. This bold move allowed authorities to neutralize the threat without relying on individual device owners to take action.
-
APT28 targets SOHO routers with DNS hijacking
• 200+ orgs impacted
• 5,000 devices compromised
• AiTM attacks enable credential theftHome networks are now attack vectors.
-
Das Bundesamt für Verfassungsschutz schlägt Alarm: Die Hackergruppe APT28, auch bekannt als Fancy Bear, dem russischen Militärgeheimdienst GRU zugerechnet – hat weltweit tausende TP-Link-Router infiltriert. Das Ziel: militärische Informationen, Regierungsdaten und Erkenntnisse über kritische Infrastrukturen (KRITIS). In Deutschland wurden rund 30 verwundbare Geräte identifiziert – in einzelnen Fällen wurde die Kompromittierung bereits bestätigt. #APT28 #Verfassungsschutz #KRITIS #Cybercrime
-
Russische Hacker von #APT28 haben weltweit zehntausende Router gekapert, um Passwörter abzugreifen - auch in Deutschland wurden Geräte von #MikroTik und TP-Link kompromittiert. https://winfuture.de/news,157972.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Russische Hacker von #APT28 haben weltweit zehntausende Router gekapert, um Passwörter abzugreifen - auch in Deutschland wurden Geräte von #MikroTik und TP-Link kompromittiert. https://winfuture.de/news,157972.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Warnung aus UK 🇬🇧 : Russische Cyberkriminelle kapern Router zum Passwort-Klau | heise online https://www.heise.de/news/Warnung-aus-UK-Russische-Cyberkriminelle-kapern-Router-zum-Passwort-Klau-11247959.html #CyberCrime #Russland 🇷🇺 #Russia 🇷🇺 #APT28 #ForestBlizzard #FancyBear #STRONTIUM #Sednit #Sofacy
-
Warnung aus UK 🇬🇧 : Russische Cyberkriminelle kapern Router zum Passwort-Klau | heise online https://www.heise.de/news/Warnung-aus-UK-Russische-Cyberkriminelle-kapern-Router-zum-Passwort-Klau-11247959.html #CyberCrime #Russland 🇷🇺 #Russia 🇷🇺 #APT28 #ForestBlizzard #FancyBear #STRONTIUM #Sednit #Sofacy
-
APT28 Hijacks SOHO Routers in Global DNS Espionage Push
Your home router, that innocent-looking box under your desk, can be turned against you: a Russia-linked cyber threat group, APT28, has been hijacking insecure SOHO routers worldwide to fuel a massive DNS espionage campaign. By exploiting vulnerabilities in popular router brands like MikroTik and TP-Link, they've been manipulating DNS settings to spy on…
https://osintsights.com/apt28-hijacks-soho-routers-in-global-dns-espionage-push
-
Russia Hacked Routers to Steal Microsoft Office Tokens
https://krebsonsecurity.com/2026/04/russia-hacked-routers-to-steal-microsoft-office-tokens/
#NationalCyberSecurityCentre #InternetofThings(IoT) #Ne'er-Do-WellNews #ALittleSunshine #MicrosoftOffice #LatestWarnings #TheComingStorm #BlackLotusLabs #ForestBlizzard #DannyAdamitis #RyanEnglish #FancyBear #MikroTik #TP-Link #APT28 #Lumen
-
Russia Hacked Routers to Steal Microsoft Office Tokens
https://krebsonsecurity.com/2026/04/russia-hacked-routers-to-steal-microsoft-office-tokens/
#NationalCyberSecurityCentre #InternetofThings(IoT) #Ne'er-Do-WellNews #ALittleSunshine #MicrosoftOffice #LatestWarnings #TheComingStorm #BlackLotusLabs #ForestBlizzard #DannyAdamitis #RyanEnglish #FancyBear #MikroTik #TP-Link #APT28 #Lumen
-
APT28 Hijacks Routers to Steal Credentials via Malicious DNS Servers
Beware of invisible hands rerouting your online traffic: a state-linked Russian hacking group, APT28, has been hijacking routers to intercept credentials by manipulating DNS servers, putting your online security at risk. This stealthy tactic allows them to capture user authentication data, compromising your digital identity.
https://osintsights.com/apt28-hijacks-routers-to-steal-credentials-via-malicious-dns-servers
#Apt28 #Russia #MaliciousDnsServers #RouterHijacking #CredentialTheft
-
Law Enforcement Disrupts APT28's Router DNS Hijack Operation
In a major breakthrough, an international coalition of law enforcement authorities and private companies has successfully disrupted a sneaky DNS hijack operation by APT28, known as FrostArmada, that targeted home network routers to steal Microsoft account credentials. This operation thwarted the hackers' plan to intercept traffic and harvest cloud account…
https://osintsights.com/law-enforcement-disrupts-apt28s-router-dns-hijack-operation
-
📰 Russia's Pawn Storm (APT28) Targets Defense Supply Chain with New 'PRISMEX' Malware and Zero-Day
🇷🇺 Russia's APT28 (Pawn Storm) is targeting the defense supply chain with new 'PRISMEX' malware, exploiting a Windows zero-day (CVE-2026-21513). 🛡️ #APT28 #PawnStorm #ZeroDay #CyberWarfare
-
Operation Roundish: Uncovering an APT28 Roundcube Toolkit Used Against Ukrainian Government Targets
#APT28 #Roundcube
https://hunt.io/blog/operation-roundish-apt28-roundcube-exploitation -
Operation Roundish: Uncovering an APT28 Roundcube Toolkit Used Against Ukrainian Government Targets
#APT28 #Roundcube
https://hunt.io/blog/operation-roundish-apt28-roundcube-exploitation -
Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513
#CVE_2026_21513 #APT28
https://www.akamai.com/blog/security-research/2026/feb/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis -
Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure
#APT28
https://lab52.io/blog/operation-macromaze-new-apt28-campaign-using-basic-tooling-and-legit-infrastructure/ -
APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure
#APT28 #CVE_2026_21509
https://www.trellix.com/blogs/research/apt28-stealthy-campaign-leveraging-cve-2026-21509-cloud-c2/ -
Op Neusploit: Russian APT28 Uses Microsoft Office Flaw in Malware Attacks https://hackread.com/op-neusploit-russia-apt28-microsoft-office-malware/ #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #Microsoft #Neusploit #Security #Malware #Romania #Ukraine #Windows #europe #Russia #APT28
-
📢⚠️ Operation Neusploit is an #APT28-linked campaign abusing a critical but patched Microsoft Office OLE flaw to deliver malware across Ukraine, Slovakia, and Romania.
Read: https://hackread.com/op-neusploit-russia-apt28-microsoft-office-malware/
-
Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability https://www.securityweek.com/russias-apt28-rapidly-weaponizes-newly-patched-office-vulnerability/ #Malware&Threats #Vulnerabilities #Nation-State #exploited #Featured #Office #Russia #APT28 #APT