US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers
The FBI deployed a method to unplug US-based routers compromised by APT28 from the threat actor’s malicious network
Russian military intelligence (GRU) hacking group active since mid-2000s. Known for targeting NATO governments, military organizations, and political entities.
Also known as: apt28, fancy bear, sofacy, pawn storm, strontium, forest blizzard, iron twilight, sednit
The FBI deployed a method to unplug US-based routers compromised by APT28 from the threat actor’s malicious network
Newly identified malicious campaigns are linked to virtual private servers modified by APT28 to operate as malicious DNS servers
The resurgence of one of Russia’s most notorious APT groups
January 2026 saw 23 actively exploited CVEs, including APT28’s Microsoft Office zero-day and critical auth bypass flaws impacting enterprise systems.