UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot

A42 southbound between J14 and J13 | Southbound | Vehicle Fire

12 April 2026
Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times

Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times

12 April 2026

A42 southbound between J14 and J13 | Southbound | Congestion

12 April 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » APT28 exploit routers to enable DNS hijacking operations | National Cyber Security Centre
News

APT28 exploit routers to enable DNS hijacking operations | National Cyber Security Centre

By uk-times.com12 April 2026No Comments2 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

The AitM activity could be conducted against both user browser sessions and desktop applications. Harvested authentication material could include both passwords and OAuth or similar authentication tokens. Subsequent malicious logins using this stolen data may originate from further infrastructure not listed in this advisory.

It is believed that the DNS hijacking operations are opportunistic in nature, with the actor gaining visibility of a large pool of candidate target users then filtering down users at each stage in the exploitation chain to triage for victims of likely intelligence value.

TP-Link router exploitation

One of the router models that APT28 exploited for their DNS poisoning operations was the TP-Link WR841N, likely using CVE-2023-50224 [T1584.008, T1588.006]. This vulnerability enables an unauthenticated attacker to obtain information such as password credentials via specially crafted HTTP GET requests.

Having obtained the credentials for a router, the actor was then able to send a second specially crafted HTTP GET request to alter the DHCP DNS settings of that router.

The GET request would typically set the router’s primary DNS server to a malicious IP address, whilst also setting the secondary DNS server to the original primary DNS server’s IP address. On occasion both the primary and secondary DNS server had been set to malicious IP addresses, indicating that a router had likely been exploited multiple times.

Other TP-Link router models were also targeted by APT28 to enable their DNS hijacking operations.  A list can be found in the Indicators of Compromise section.
 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

A42 southbound between J14 and J13 | Southbound | Vehicle Fire

12 April 2026
Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times

Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times

12 April 2026

A42 southbound between J14 and J13 | Southbound | Congestion

12 April 2026
Lebanese bury 13 officers killed by Israel as grief and rage surge ahead of talks in the US – UK Times

Lebanese bury 13 officers killed by Israel as grief and rage surge ahead of talks in the US – UK Times

12 April 2026
Trump takes the spotlight at UFC 327 in Miami, greeting Rogan and Rubio – UK Times

Trump takes the spotlight at UFC 327 in Miami, greeting Rogan and Rubio – UK Times

12 April 2026
Hole-in-one specialist Shane Lowry does it again at Augusta National – UK Times

Hole-in-one specialist Shane Lowry does it again at Augusta National – UK Times

12 April 2026
Top News

A42 southbound between J14 and J13 | Southbound | Vehicle Fire

12 April 2026
Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times

Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times

12 April 2026

A42 southbound between J14 and J13 | Southbound | Congestion

12 April 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • A42 southbound between J14 and J13 | Southbound | Vehicle Fire
  • Boy, 9, rescued after being locked in his father’s van in France for over a year – UK Times
  • A42 southbound between J14 and J13 | Southbound | Congestion
  • Lebanese bury 13 officers killed by Israel as grief and rage surge ahead of talks in the US – UK Times
  • Footy commentator James Brayshaw names and shames his famous colleagues for having WAY too much to drink at AFL event

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version