{"id":4541,"date":"2026-04-07T23:56:07","date_gmt":"2026-04-07T23:56:07","guid":{"rendered":"https:\/\/www.europesays.com\/russia\/4541\/"},"modified":"2026-04-07T23:56:07","modified_gmt":"2026-04-07T23:56:07","slug":"feds-quash-widespread-russia-backed-espionage-network-spanning-18000-devices","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/russia\/4541\/","title":{"rendered":"Feds quash widespread Russia-backed espionage network spanning 18,000 devices"},"content":{"rendered":"<p>Russian state-sponsored attackers compromised more than 18,000 routers spread across more than 120 countries to gain deeper access to sensitive networks for a large-scale espionage campaign before it was recently neutralized, researchers and authorities said Tuesday.<\/p>\n<p>Forest Blizzard, also known as APT28 and Fancy Bear, exploited known vulnerabilities to steal credentials for <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled\" rel=\"nofollow noopener\" target=\"_blank\">thousands of TP-Link routers<\/a> globally. The threat group, which is attributed to Russia\u2019s Main Intelligence Directorate of the General Staff (GRU) Military Unit 26165, hijacked domain name system settings and stole additional credentials and tokens via redirected traffic, the Justice Department said.<\/p>\n<p>The threat group established an expansive espionage network by intruding systems of <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/04\/07\/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">more than 200 organizations<\/a>, impacting at least 5,000 consumer devices, Microsoft Threat Intelligence said in a report.\u00a0<\/p>\n<p>Operation Masquerade, a collaborative takedown operation led by the FBI, aided by federal prosecutors, the National Security Division\u2019s National Security Cyber section, <a href=\"https:\/\/www.lumen.com\/blog-and-news\/en-us\/frostarmada-forest-blizzard-dns-hijacking\" rel=\"nofollow noopener\" target=\"_blank\">Lumen\u2019s Black Lotus Labs<\/a> and Microsoft Threat Intelligence, involved a series of commands designed to reset DNS settings and prevent the threat group from further exploiting its initial means of access.\u00a0<\/p>\n<p>\u201cGRU actors compromised routers in the U.S. and around the world, hijacking them to conduct espionage. Given the scale of this threat, sounding the alarm wasn\u2019t enough,\u201d Brett Leatherman, assistant director of the FBI\u2019s cyber division, said in a statement. \u201cThe FBI conducted a court-authorized operation to harden compromised routers across the United States.\u201d<\/p>\n<p>Forest Blizzard\u2019s widespread campaign involved adversary-in-the-middle attacks against domains mimicking legitimate services, including Microsoft Outlook Web Access. This allowed attackers to intercept passwords, OAuth tokens, credentials for Microsoft accounts, and other services and cloud-hosted content.\u00a0<\/p>\n<p>Microsoft insists company-owned assets or services were not compromised as part of the campaign.<\/p>\n<p>The threat group targeted network edge devices, including TP-Link and MicroTik routers, opportunistically before it identified sensitive targets of intelligence interest to the Russian government, including people in the military, government and critical infrastructure sectors.\u00a0<\/p>\n<p>Victims, according to researchers, include government agencies and organizations in the IT, telecom and energy sectors. Lumen identified other victims associated with Afghanistan\u2019s government and others linked to foreign affairs and national law enforcement agencies in North Africa, Central America and Southeast Asia. An unnamed European country\u2019s national identity platform was also impacted, the company said.<\/p>\n<p>Lumen did not find evidence of any compromised U.S. government agencies as part of this campaign, but warned that the activity poses a grave national security threat.<\/p>\n<p>While the full scope of Forest Blizzard\u2019s accomplishments remain under investigation, researchers are confident the bleeding of sensitive information has stopped.\u00a0<\/p>\n<p>\u201cThe campaign has ceased,\u201d Danny Adamitis, distinguished engineer at Black Lotus Labs, told CyberScoop. \u201cWe have observed a gradual decline in communications associated with this infrastructure over the past several weeks.\u201d<\/p>\n<p>Lumen said it observed widespread router exploitation and DNS redirection beginning in August, the day after the United Kingdom\u2019s National Cyber Security Centre published a <a href=\"https:\/\/www.ncsc.gov.uk\/sites\/default\/files\/documents\/ncsc-mar-authentic_antics.pdf\" rel=\"nofollow noopener\" target=\"_blank\">malware analysis report<\/a> about a tool used to steal Microsoft Office credentials. The U.K.\u2019s NCSC on Tuesday published details about <a href=\"https:\/\/www.ncsc.gov.uk\/news\/apt28-exploit-routers-to-enable-dns-hijacking-operations\" rel=\"nofollow noopener\" target=\"_blank\">APT28\u2019s DNS hijacking campaign<\/a>, including indicators of compromise.<\/p>\n<p>The Justice Department and FBI, acting on a court order, remediated compromised routers in the United States after collecting evidence on Forest Blizzard\u2019s activity. The FBI said Russia\u2019s GRU weaponized routers owned by Americans in more than 23 states to steal sensitive government, military and critical infrastructure information.<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.europesays.com\/russia\/wp-content\/uploads\/2026\/04\/MattKapko.jpg\" alt=\"Matt Kapko\"\/><\/p>\n<p>\n\t\t\tWritten by Matt Kapko<br \/>\n\t\t\tMatt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"Russian state-sponsored attackers compromised more than 18,000 routers spread across more than 120 countries to gain deeper access&hellip;\n","protected":false},"author":2,"featured_media":4542,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3159,3160,3224,22,3225,3226,3227,3228,3162,3229,3230,3163,5,3231,3232],"class_list":{"0":"post-4541","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-russia","8":"tag-apt28","9":"tag-black-lotus-labs","10":"tag-department-of-justice-doj","11":"tag-espionage","12":"tag-fancy-bear","13":"tag-federal-bureau-of-investigation-fbi","14":"tag-forest-blizzard","15":"tag-gru","16":"tag-microsoft","17":"tag-microsoft-threat-intelligence","18":"tag-microtik","19":"tag-ncsc","20":"tag-russia","21":"tag-tp-link-technologies","22":"tag-united-kingdom-u-k"},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/posts\/4541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/comments?post=4541"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/posts\/4541\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/media\/4542"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/media?parent=4541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/categories?post=4541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/russia\/wp-json\/wp\/v2\/tags?post=4541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}