#EdgeRouters
If you have a #Linux box out there, specially - but not limited to - #Ubiquiti boxes, you should really check whether your sshd is backdoored or not. Instructions in our blogpost. 😉 #apt28 #sshdoor #ngioweb #malware

research.trendmicro.com/router-roule...
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
research.trendmicro.com
May 9, 2024 at 10:40 PM
GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations gbhackers.com/gru-linked-a...
GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations
A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters.
gbhackers.com
June 14, 2026 at 5:53 PM
Cybersecurity Agencies Warn Ubiquiti EdgeRouter Users of APT28's MooBot Threat
Cybersecurity Agencies Warn Ubiquiti EdgeRouter Users of APT28's MooBot Threat
Nations unite to warn against the MooBot botnet threat targeting Ubiquiti EdgeRouters.
thehackernews.com
February 28, 2024 at 6:21 AM
Headlines like this drive me batty. There's no Ubiquiti 0-Day:

"'EdgeRouters are often shipped with default credentials and limited to no firewall protections to accommodate wireless internet service providers (WISPs),' the joint advisory warns."

Default creds, like always.
Russian hackers hijack Ubiquiti routers to launch stealthy attacks
Russian APT28 military hackers are using compromised Ubiquiti EdgeRouters to evade detection, the FBI says in a joint advisory issued with the NSA, the U.S. Cyber Command, and international partners.
www.bleepingcomputer.com
February 27, 2024 at 6:38 PM
📌 FBI Disrupts GRU Operation; Iranian Threat Actors Target U.S. Infrastructure; New ClickFix Attack Te... https://www.cyberhub.blog/article/23704-fbi-disrupts-gru-operation-iranian-threat-actors-target-us-infrastructure-new-clickfix-attack-technique-observed
FBI Disrupts GRU Operation; Iranian Threat Actors Target U.S. Infrastructure; New ClickFix Attack Technique Observed
The FBI disrupted a GRU (Russian military intelligence) operation that hijacked Ubiquiti EdgeRouters to conduct cyber espionage and other malicious activities. Separately, Iranian state-sponsored threat actors exploited programmable logic controllers (PLCs) in U.S. critical infrastructure, including water and energy sectors. A new attack technique called ClickFix was observed bypassing Apple’s Terminal security mitigations by tricking users into executing malicious scripts via fake update prompts. No specific dates, CVE IDs, or technical details about the exploited PLC vulnerabilities were provided. The incidents highlight ongoing threats from nation-state actors targeting infrastructure and endpoint devices.
www.cyberhub.blog
April 11, 2026 at 11:07 PM
GRU関連APT28がMooBotボットネットと侵害されたEdgeRouterを使用してサイバー作戦を実施

GRUと関連のある侵入グループAPT28(別名Fancy Bear、Sofacy、Forest Blizzard、Pawn Storm)による注目すべき作戦転換は、MooBotボットネットと侵害されたEdgeRouterを組み合わせて、回復力のあるサイバー作戦を可能にすることである。

この変化は、APT28が長年注力してきたNATO、ウクライナ、重要インフラへの攻撃をさらに強化するものであり、主要な機能を従来のクラウドVPSや汎用ホスティングからネットワークエッジへと移行させて...
GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations
A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters.
gbhackers.com
July 6, 2026 at 8:12 PM
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks
One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor known as Fancy Bear, formally tracked as APT28 and attributed to Russia’s military intelligence unit GRU Unit 26165, has been quietly shifting how it runs cyberattack operations. Instead of relying on traditional infrastructure, the group now hijacks home routers and consumer devices to build a shadow network nearly impossible to trace. For over two decades, APT28 has targeted government bodies, defense organizations, diplomatic missions, and critical infrastructure, focusing heavily on NATO member states and Ukraine. The group operates under more than 30 known aliases, including Forest Blizzard, Sofacy, Pawn Storm, and Sednit. What makes its latest campaign especially alarming is how invisible it has become, with attack traffic blending into normal internet activity. Analysts from Sekoia, who have been tracking APT28 for several years, identified a significant structural shift in how the group manages its attack infrastructure. Sekoia said in a report shared with Cyber Security News (CSN) that APT28 moved large portions of its operations onto compromised SOHO routers and edge devices, replacing rented virtual private servers it previously used as command centers. The scale of this infrastructure is striking. At its peak in December 2025, researchers observed more than 18,000 unique IP addresses across 120 countries communicating with APT28-controlled servers. Timeline (Source – Sekoia) Around 200 organizations and 5,000 consumer devices were affected, with victims coming primarily from foreign ministries, law enforcement agencies, and IT hosting providers. APT28’s tradecraft has also evolved sharply. The group shifted from a stable malware framework to deploying short-lived, single-purpose tools discarded the moment they are exposed. It also experimented with an AI-driven infostealer called LameHug, which queries a live AI model to generate attack commands on the fly. This blend of disposable tools, cloud abuse, and router hijacking makes APT28 one of the most capable threat actors active today. Fancy Bear Hackers Abuse EdgeRouters and Cloud Services The most significant tactical shift is APT28’s takeover of consumer-grade routers. The group repurposed a criminal botnet built with the MooBot malware, seizing control of hundreds of Ubiquiti EdgeRouters in April 2022. The botnet served three purposes: relaying stolen authentication hashes toward Microsoft Exchange, hosting phishing pages on residential IP addresses, and running custom Python scripts on the hijacked routers. The FBI’s Operation Dying Ember dismantled this network in 2024. Even after the takedown, more than 350 datacenter servers were still calling back to attacker infrastructure , showing just how hard this kind of botnet is to fully uproot. In 2026, APT28 broadened the same approach with a campaign called FrostArmada, this time targeting MikroTik and TP-Link routers. The attackers rewrote DNS settings to redirect traffic through their own controlled servers. Every device on affected networks would unknowingly funnel its login requests through APT28 nodes, enabling silent theft of credentials and OAuth tokens for services like Microsoft 365. Cloud Services as a Covert Command Channel Beyond router hijacking, APT28 routes malware communications through legitimate cloud platforms to avoid detection. In Operation Phantom Net Voxel, the group deployed a custom C++ backdoor called BeardShell , which uses a cloud storage API as its command channel. To anyone monitoring the traffic, it looks like a connection to a trusted cloud service. The group can swap cloud providers easily. Researchers observed the same attack chain reused with a different file-hosting platform months later, confirming that rotating the cloud backend is now routine. A keylogger called Slimagent, found on the same operator infrastructure, was linked to direct code lineage from X-Agent, APT28’s signature implant used over a decade ago. To reduce exposure, organizations should keep router firmware updated, change default credentials, and disable unused remote management features. Enterprises using cloud services should enforce phishing-resistant multi-factor authentication and regularly audit OAuth token permissions. The FBI’s Internet Crime Complaint Center published a public alert urging home users and small businesses to review router settings after FrostArmada was disclosed. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks appeared first on Cyber Security News .
cybersecuritynews.com
June 12, 2026 at 6:58 PM
Russia-linked APT28 compromised Ubiquiti EdgeRouters to facilitate cyber operations
Russia-linked APT28 compromised Ubiquiti EdgeRouters to facilitate cyber operations
Russian cyberspies are compromising Ubiquiti EdgeRouters to evade detection, warns a joint advisory published by authorities.
securityaffairs.com
February 28, 2024 at 12:07 PM
Russian hackers hijack Ubiquiti routers to launch stealthy attacks
Russian hackers hijack Ubiquiti routers to launch stealthy attacks
Russian APT28 military hackers are using compromised Ubiquiti EdgeRouters to evade detection, the FBI says in a joint advisory issued with the NSA, the U.S. Cyber Command, and international partners.
www.bleepingcomputer.com
February 27, 2024 at 5:32 PM
Having spent the afternoon testing BGP configs on Ubiquiti EdgeRouters… yikes.

What an awful CLI.
November 19, 2024 at 4:34 AM
Fancy Bear Hackers abuse EdgeRouters and Cloud Services to launch Stealthy Cyberattacks:

cybersecuritynews.com/fancy-bear-h...
June 13, 2026 at 9:10 AM
"The FBI and partners from 10 other countries are urging owners of Ubiquiti EdgeRouters to check their gear for signs they’ve been hacked and are being used to conceal ongoing malicious operations by Russian state hackers."
arstechnica.com?p=2006319
Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warns
Six years on, routers remain a favorite post for concealing malicious activities.
arstechnica.com
February 28, 2024 at 5:38 AM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Friday, June 12, 2026
GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations
A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters.
gbhackers.com
June 13, 2026 at 12:18 PM
APT28 hijacks EdgeRouters and abuses cloud services for stealthy cyberattacks, evading detection. #APT28 #FancyBear #CyberSecurity #EdgeRouters #CloudSecurity #CyberAttacks thedailytechfeed.com/fancy-bear-e...
June 12, 2026 at 7:22 PM
#Russia #EdgeRouters The devices often ship with default credentials and have limited firewall protections. EdgeRouters will not automatically update their firmware unless configured by the consumer. www.nsa.gov/Press-Room/P...
Russian Cyber Actors Use Compromised Routers to Facilitate Cyber Operations
FORT MEADE, Md. – The National Security Agency (NSA) has joined the Federal Bureau of Investigation (FBI) and other co-sealers to publish a Cybersecurity Advisory (CSA), “Russian Cyber Actors Use
www.nsa.gov
January 5, 2025 at 8:26 PM
GRU Botnet Puppet Show Rolls On While Everyone Pretends Not to See It
PANIC 67% | Lag 4.58h | APT28-linked operators are being tied to MooBot botnet infrastructure and compromised EdgeRouters fo
#AfterShockIndex
READ MORE
June 23, 2026 at 12:38 AM
APT28 Builds Its Own Internet While Everyone Else Files Reports
PANIC 76% | Lag 0.0h | APT28 is abusing compromised SOHO routers and edge devices, including Ubiquiti EdgeRouters, MikroTik
#AfterShockIndex
READ MORE
June 21, 2026 at 6:10 PM
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor k...

#cyber #security #news #Threats #cyber #security #Cyber #Security #News

Origin | Interest | Match
June 12, 2026 at 7:16 PM