UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
NFL star-turned-UFL coach Ted Ginn Jr. arrested on DUI charge a day before a game… and his 41st birthday

NFL star-turned-UFL coach Ted Ginn Jr. arrested on DUI charge a day before a game… and his 41st birthday

12 April 2026
Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times

Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times

12 April 2026
Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times

Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times

12 April 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » APT28 exploit routers to enable DNS hijacking operations | National Cyber Security Centre
News

APT28 exploit routers to enable DNS hijacking operations | National Cyber Security Centre

By uk-times.com12 April 2026No Comments2 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

The AitM activity could be conducted against both user browser sessions and desktop applications. Harvested authentication material could include both passwords and OAuth or similar authentication tokens. Subsequent malicious logins using this stolen data may originate from further infrastructure not listed in this advisory.

It is believed that the DNS hijacking operations are opportunistic in nature, with the actor gaining visibility of a large pool of candidate target users then filtering down users at each stage in the exploitation chain to triage for victims of likely intelligence value.

TP-Link router exploitation

One of the router models that APT28 exploited for their DNS poisoning operations was the TP-Link WR841N, likely using CVE-2023-50224 [T1584.008, T1588.006]. This vulnerability enables an unauthenticated attacker to obtain information such as password credentials via specially crafted HTTP GET requests.

Having obtained the credentials for a router, the actor was then able to send a second specially crafted HTTP GET request to alter the DHCP DNS settings of that router.

The GET request would typically set the router’s primary DNS server to a malicious IP address, whilst also setting the secondary DNS server to the original primary DNS server’s IP address. On occasion both the primary and secondary DNS server had been set to malicious IP addresses, indicating that a router had likely been exploited multiple times.

Other TP-Link router models were also targeted by APT28 to enable their DNS hijacking operations.  A list can be found in the Indicators of Compromise section.
 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times

Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times

12 April 2026
Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times

Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times

12 April 2026

Issue details – Change to the approved Civil Registration fees for Marriage and Civil Partnership services

12 April 2026
Brentford boss Keith Andrews hails ‘very special’ Igor Thiago – UK Times

Brentford boss Keith Andrews hails ‘very special’ Igor Thiago – UK Times

12 April 2026

Shropshire Council seeks two ‘independent persons’ to support Code of Conduct allegations

12 April 2026
Pope Leo condemns ‘delusion of omnipotence’ fueling Iran-US war in fresh plea for peace – UK Times

Pope Leo condemns ‘delusion of omnipotence’ fueling Iran-US war in fresh plea for peace – UK Times

12 April 2026
Top News
NFL star-turned-UFL coach Ted Ginn Jr. arrested on DUI charge a day before a game… and his 41st birthday

NFL star-turned-UFL coach Ted Ginn Jr. arrested on DUI charge a day before a game… and his 41st birthday

12 April 2026
Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times

Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times

12 April 2026
Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times

Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times

12 April 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • NFL star-turned-UFL coach Ted Ginn Jr. arrested on DUI charge a day before a game… and his 41st birthday
  • Fabian Hurzeler urges Brighton ‘to go all in’ as Seagulls chase European place – UK Times
  • Sunday’s briefing: Arsenal title bid dented by loss and Bayern win without Kane – UK Times
  • Issue details – Change to the approved Civil Registration fees for Marriage and Civil Partnership services
  • How legendary TV star Bruce McAvaney angered his doctor and wife after being diagnosed with leukaemia

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version