Fancy Bear Hackers Are Abusing Routers and Cloud Services to Hide Cyberattacks
Fancy Bear, also known as APT28, Forest Blizzard, Sofacy, Pawn Storm, and Sednit, is shifting more of its cyber operations away from traditional attacker servers and into compromised routers and legitimate cloud services.
A new Sekoia report says the Russian state-linked hacking group has steadily changed its infrastructure, tooling, and attack tempo over more than two decades. Recent campaigns show a clear pattern: APT28 now leans heavily on edge devices, disposable tools, and cloud-based command channels to make its activity harder to block.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The latest concern is router hijacking. According to Microsoft Threat Intelligence, Forest Blizzard has compromised insecure home and small-office routers since at least August 2025, then changed their DNS settings to redirect traffic through attacker-controlled infrastructure.
APT28 Is Turning Routers Into Stealth Infrastructure
The UK’s National Cyber Security Centre warned in April 2026 that APT28 has been exploiting vulnerable routers to enable DNS hijacking, adversary-in-the-middle attacks, and theft of passwords, OAuth tokens, and other credentials.
This approach gives attackers a major advantage. Traffic from a hacked router can look like ordinary residential or small-business internet activity. That makes it harder for defenders to rely on IP reputation, datacenter blocking, or basic network filtering.

Lumen’s Black Lotus Labs tracked the 2025 and 2026 DNS hijacking activity as FrostArmada. At peak activity in December 2025, Lumen observed more than 18,000 unique IP addresses across more than 120 countries communicating with Forest Blizzard infrastructure.
| Operation or activity | Main tactic | What it enabled |
|---|---|---|
| Operation Dying Ember | Ubiquiti EdgeRouter botnet disruption | Removal of GRU-controlled files and scripts from compromised routers using MooBot malware |
| FrostArmada | DNS hijacking through MikroTik and TP-Link routers | Credential and token theft through attacker-controlled DNS resolvers |
| Operation Masquerade | Court-authorized disruption of DNS hijacking infrastructure | Reset of malicious DNS settings on compromised routers in the United States |
| BeardShell and SlimAgent | Cloud-based command and control | Long-term surveillance and command execution through legitimate cloud services |
| LAMEHUG | LLM-assisted malware commands | Dynamic generation of reconnaissance and data theft commands |
How the Router Attacks Work
In the newer campaigns, APT28 does not always need malware on the victim’s laptop or phone. Instead, the attackers compromise the router upstream of those devices and change its DNS configuration.
Once that happens, connected devices can inherit malicious DNS settings through DHCP. The attacker-controlled DNS server can then observe requests and, for selected targets, return fake responses for services such as Outlook Web Access or other login portals.
The Microsoft analysis says the campaign affected more than 200 organizations and 5,000 consumer devices, with exposure across government, IT, telecommunications, and energy sectors.
- Compromised routers can redirect DNS traffic without changing endpoint devices.
- Victims may see normal websites unless the attacker targets a specific login flow.
- Credential theft can happen through adversary-in-the-middle infrastructure.
- Remote workers can expose enterprise accounts through insecure home routers.
Cloud Services Make APT28 Harder to Detect
APT28 is also abusing legitimate cloud services for command and control. The latest Sekoia analysis describes BeardShell as a custom C++ backdoor that can use cloud storage APIs for command traffic, helping malicious communication blend into trusted cloud activity.
ESET researchers also linked SlimAgent to older X-Agent code lineage, suggesting that APT28 has not abandoned its older tooling so much as rebuilt parts of it for modern operations.
The group is also testing newer attack concepts. Cato Networks analyzed LAMEHUG, a malware family first reported by CERT-UA and linked to APT28 with moderate confidence, which uses a large language model to generate commands during an attack.
Law Enforcement Is Disrupting the Router Networks
The U.S. Justice Department said Operation Dying Ember neutralized a network of hundreds of compromised SOHO routers in January 2024. The routers had been infected with MooBot malware, which GRU hackers repurposed for espionage.
In April 2026, the Justice Department and FBI announced Operation Masquerade, a court-authorized operation that reset malicious DNS settings and removed GRU-controlled resolvers from compromised TP-Link routers in the United States.
The FBI’s Internet Crime Complaint Center also warned router owners and small businesses that Russian GRU actors have exploited vulnerable routers worldwide to steal sensitive military, government, and critical infrastructure information.
What Router Owners and Companies Should Do Now
The risk is not limited to government networks. Any organization with remote staff, unmanaged routers, older networking equipment, or weak DNS monitoring can face exposure if attacker-controlled routers sit between users and cloud services.
The NCSC guidance recommends securing device management interfaces, keeping devices updated, using multi-factor authentication, and monitoring for suspicious DNS behavior.
The IC3 alert urges users to change default usernames and passwords, disable internet-facing remote management, update router firmware, and replace end-of-life devices.
| Priority | Action | Why it matters |
|---|---|---|
| High | Replace unsupported routers | End-of-life devices often no longer receive security patches. |
| High | Update router firmware | Firmware updates can close known vulnerabilities used for initial access. |
| High | Review DNS settings | Unexpected DNS resolvers can indicate hijacking or misconfiguration. |
| Medium | Disable remote management | Internet-exposed admin panels increase the attack surface. |
| Medium | Use phishing-resistant MFA | Strong authentication reduces the impact of stolen passwords. |
APT28’s latest activity shows why routers now matter in enterprise security. The group is not only attacking endpoints and inboxes. It is targeting the infrastructure that sits quietly between users, cloud services, and corporate accounts.
FAQ
Fancy Bear is a Russian state-linked cyber-espionage group also tracked as APT28, Forest Blizzard, Sofacy, Pawn Storm, and Sednit. Western governments and security researchers have linked the group to Russia’s GRU military intelligence service.
The group compromises vulnerable home and small-office routers, changes DNS settings, and redirects selected traffic through attacker-controlled infrastructure. This can enable credential theft and adversary-in-the-middle attacks without installing malware on every victim device.
FrostArmada is the name used by Lumen’s Black Lotus Labs for a Forest Blizzard campaign that compromised MikroTik and TP-Link routers and used DNS hijacking to route authentication traffic through attacker-controlled infrastructure.
Operation Masquerade was a 2026 court-authorized U.S. Justice Department and FBI operation that disrupted a GRU-controlled DNS hijacking network and reset malicious DNS settings on compromised routers in the United States.
Users should update router firmware, replace unsupported devices, change default admin passwords, disable remote management from the internet, verify DNS settings, and use strong multi-factor authentication for cloud and email accounts.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages