FR
live

DOJ and FBI dismantle the GRU’s DNS hijacking network

The US Justice Department and FBI announced the takedown of a network of SOHO routers compromised by Russia’s GRU, which was hijacking DNS lookups to intercept credentials and encrypted email. The lesson in one line: the home router has become the intelligence services’ preferred interception point, and it must be defended like an attack surface.

A small dark home router sitting on a shelf, a grey Ethernet cable unplugged and hanging from its LAN port, a single amber LED lit.

Since at least 2024. Russia’s GRU — specifically the 85th Main Special Service Center (85th GTsSS), tracked as APT28, Fancy Bear and Forest Blizzard — has been exploiting vulnerable routers worldwide to intercept sensitive military, government and critical-infrastructure information. April 7, 2026. The UK’s NCSC publishes its advisory “APT28 exploit routers to enable DNS hijacking operations”. Summer 2026. The DOJ and FBI, backed by the NSA and fifteen international partners, announce the disruption of a network of compromised SOHO routers that formed the backbone of these operations.

What is being targeted here is not a spectacular exploit but a layer everyone trusts: DNS resolution. The GRU turned it into an interception point, and that is where defense must focus.

DNS hijacking, the quietest method

When an analyst sees encrypted traffic flowing over VPN or TLS, they assume the content is protected. The GRU defeats that assumption upstream, at the router. The attacker changes the device’s DHCP and DNS settings to inject actor-controlled DNS resolvers. Every connected device — laptops, phones, IoT gear — inherits the modified settings, with nothing installed and nothing clicked by the user.

What follows is mechanical. The GRU-controlled infrastructure resolves and captures lookups for every domain name. For specific targeted domains and services — most notably Microsoft Outlook Web Access — it returns fraudulent DNS answers that redirect the victim to an attacker-controlled server. If the user clicks through the certificate warning, the attacker runs an adversary-in-the-middle (AitM) attack and reads the traffic in plaintext, even though it was “protected” by SSL/TLS.

The haul matches the subtlety: passwords, authentication tokens, emails and browsing history — everything that should have stayed encrypted. The FBI describes the triage: the GRU first compromises a broad pool of US and global victims indiscriminately, then filters down to users connected to military, government and critical infrastructure.

The entry point is not enterprise infrastructure but the small-office or home router. The FBI documents the exploitation of TP-Link routers via CVE-2023-50224, a known flaw that grants control of the device. These boxes share three structural weaknesses: firmware that is rarely updated, default credentials that are never changed, and remote-management interfaces left exposed to the Internet.

This inverts the geography of the threat. The GRU did not need to breach a corporate perimeter: it harvested the keys to the home network, exactly where remote work has moved a slice of sensitive traffic. An employee reading corporate email from a personal box exposes the organization without the IT department having any control over that router.

CISA has made the point in its guidance on edge-device security: these devices are no longer accessories but attack surfaces in their own right — to be inventoried, patched and monitored like servers.

A takedown that targets infrastructure, not the exploit

The DOJ and FBI operation is the most instructive part. It does not target a software vulnerability — CVE-2023-50224 remains the vendor’s to fix — but the resolution infrastructure: the network of compromised routers and the controlled resolvers running the machine. It is the same logic as botnet takedowns: cut the central point of control rather than neutralizing one IP at a time.

The coalition is unusually broad. Alongside the FBI and NSA sit fifteen partners: Canada, Czechia, Denmark, Estonia, Finland, Germany, Italy, Latvia, Lithuania, Norway, Poland, Portugal, Romania, Slovakia and Ukraine. DNS hijacking respects no borders — a router compromised in Prague can intercept the mail of an employee in Berlin — and neither does the response.

The NCSC-UK had already published, on April 7, 2026, the technical indicators and the modus operandi, with a clear instruction: end-of-support SOHO routers must be replaced, not merely patched.

Why DNS is so hard to defend

The difficulty of this kind of campaign lies in the nature of DNS itself. A device’s client does not, by default, verify that the resolver answering it is legitimate: it trusts whatever the DHCP server assigned it. If the attacker controls DHCP, they control all downstream resolution, with no alert firing on the compromised device.

The “DNSSEC will fix this” reflex does not hold here. DNSSEC authenticates the zone’s answers, not the connection between the client and the resolver. An attacker-controlled resolver can answer fraudulently for domains it resolves itself, or relay modified traffic — the legitimate domain’s DNSSEC does not stop the AitM at the transport layer. Real defense therefore lives at the router and the resolver, not in the content of the answers.

That is what makes hijacking so profitable: it exploits the default trust of the resolution layer, the one nobody watches because “DNS just works”.

What to actually do

Defense plays out at three levels, none of which requires a state-sized security budget.

  • At the device. Upgrade end-of-support routers, apply recent firmware, change default credentials, and above all disable remote management exposed to the Internet. A router that cannot be reached from outside cannot be recruited from outside.
  • At the network. Regularly check the DNS and DHCP settings of edge devices: an unknown resolver appearing in a box’s configuration is a hijack in progress, not a quirk.
  • At the user. Remind people to never click through a certificate warning — that is precisely the door the AitM walks through. For remote work, enforce a corporate VPN and hardened application configs rather than letting personal devices touch sensitive services directly.

CISA’s recommendation sums it up: edge-device security must be treated as a priority, not a postscript to the IT estate.

Verdict

If you run a corporate network, add the remote workers’ SOHO routers to your scope of responsibility: they are now the most profitable interception point for a state actor, and they escape most inventories. Checking the configured DNS resolvers on edge devices is the highest-value control you can deploy this week.

If you are an individual or a small business, the most effective measure is discipline rather than technology: replace end-of-support routers, change default passwords, switch off remote management, and treat a certificate warning as something you never ignore. The GRU is counting on you to treat it as a detail.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

The FBI takes down QScan and QTRouter, the obfuscation network hiding China’s intrusions

On August 26, 2026, the U.S. Department of Justice and the FBI seized the domains of QScan and QTRouter, two platforms run by a Chinese group that concealed the origin of intrusions against U.S. critical infrastructure. The lesson outlives the news cycle: network obfuscation is now an industrialized service, and it breaks where the attacker has the least redundancy.

← Back to the feed

Type at least two characters.

navigate open esc dismiss