Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagebotnet-infrastructuredefault-credential-exposureembedded-device-vulnerability

FBI disrupts GRU router botnets used for espionage and DNS hijacking

Updated 8d agoFirst seen May 25, 20266 sources

The FBI and Justice Department said they disrupted multiple Russian GRU operations that hijacked small office/home office routers to conceal espionage activity, proxy malicious traffic, and steal credentials. In one court-authorized action, Operation Dying Ember, agents remotely accessed hundreds of compromised Ubiquiti EdgeOS routers infected with Moobot, deleted malware and related files, and temporarily changed firewall rules to cut off APT28—also tracked as Fancy Bear, Sednit, and Forest Blizzard—without disrupting normal device use. Officials said the botnet had originally been built by cybercriminals abusing internet-exposed routers with default administrator passwords before being repurposed by Russia’s GRU Unit 26165.

U.S. authorities later said a related GRU campaign also compromised SOHO routers, including TP-Link devices, to alter DNS settings and conduct adversary-in-the-middle attacks against TLS sessions, including Outlook traffic, in operations affecting government, IT, telecommunications, and energy targets. In Operation Masquerade, the FBI sent commands to infected routers to collect forensic data and reset malicious DNS configurations, removing Russian access from the devices. Microsoft and U.S. agencies linked the activity to APT28 and warned that router compromises can enable traffic redirection, credential theft, malware delivery, and denial-of-service attacks, urging organizations to patch firmware, verify DNS settings, disable unnecessary remote management, and replace end-of-life hardware.

Share:
FBI disrupts GRU router botnets used for espionage and DNS hijacking
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jun 12, 202612d ago

Researchers detail APT28's large router-and-cloud attack infrastructure

Sekoia reported that APT28/Fancy Bear had shifted heavily to compromised SOHO routers, consumer edge devices, and cloud services, with a peak in December 2025 of more than 18,000 IP addresses across 120 countries communicating with actor-controlled servers. The report also described about 200 affected organizations, roughly 5,000 consumer devices, DNS interception activity against services such as Microsoft 365, and tooling including LameHug and the BeardShell backdoor.

黑客组织Fancy Bear滥用边缘路由器与云服务发起隐秘网络攻击 - FreeBuf网络安全行业门户
Apr 8, 20263mo ago

DOJ announces Operation Masquerade against GRU router campaign

The U.S. Justice Department announced that the FBI's Operation Masquerade disrupted a GRU campaign that hijacked SOHO routers, including TP-Link devices, to alter DNS settings and steal data. The FBI sent commands to compromised routers to collect forensic information and reset malicious DNS configurations, cutting off Russian access.

Apr 7, 20263mo ago

NSA backs FBI warning on Russian GRU router threats

The NSA published a press release supporting the FBI in highlighting Russian GRU threats against routers, underscoring the national security risk posed by the campaign. The statement accompanied broader public disclosure of the activity.

Microsoft observes GRU router compromises from at least August 2025

Microsoft said the GRU-linked actor APT28/Fancy Bear/Forest Blizzard had been compromising routers since at least August 2025 to enable large-scale DNS hijacking and adversary-in-the-middle attacks. The company observed data theft affecting sectors including government, IT, telecommunications, and energy.

GRU begins DNS-hijacking router campaign tracked by U.S. prosecutors

U.S. prosecutors said a separate GRU campaign abusing hacked SOHO routers to redirect DNS traffic and steal sensitive data had been underway since at least 2024. The activity targeted victims including governments and critical infrastructure operators.

Feb 27, 20242y ago

FBI warns Kremlin-backed hackers are targeting SOHO routers

U.S. authorities publicly warned that Russian and Chinese state-backed actors were compromising small office/home office routers, including Ubiquiti devices, to support covert operations. The warning followed the February botnet disruption and highlighted ongoing router-focused threats.

Feb 15, 20242y ago

FBI disrupts GRU's Moobot-based router botnet

In the court-authorized Operation Dying Ember, the FBI remotely accessed hundreds of compromised Ubiquiti routers used by GRU Unit 26165 (APT28/Fancy Bear), deleted Moobot and related malicious files, and temporarily changed firewall rules to block Russian access. The Justice Department announced the disruption on February 15, 2024.

Cybercriminals build Moobot botnet on exposed Ubiquiti routers

Unrelated cybercriminals initially created a botnet by infecting Internet-exposed Ubiquiti EdgeOS SOHO routers running with default administrator passwords using Moobot malware. This botnet was later repurposed by Russia's GRU for espionage operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Threat actors
2 linked
Affected products
1 linked
Microsoft 365
Organizations
7 linked
TP-LinkUbiquitiMicrosoft CorporationSekoiaMikrotikCisco SystemsLumen Technologies
Breaches
3 linked
DEMOCRATICCONGRESSIONALCAMPAIGNCOMMITTEE-2024-02DEMOCRATICNATIONALCOMMITTEE-2024-02GERMANFEDERALPARLIAMENTDEUTSCHERBUNDESTAG-2024-02
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.