
A group of Russian government hackers has hijacked thousands of home and small business routers around the world as part of an ongoing campaign to steal passwords and access tokens by redirecting victims’ internet traffic, security researchers and government authorities warned on Tuesday.
This is the latest tactic from the long-running Russian hacking group known as Fancy Bear (aka APT 28), known for high-profile hacking and espionage activities, including the 2016 Democratic National Committee breach and the devastating 2022 hack of satellite provider Viasat. Fancy Bear is widely believed to be part of the Russian intelligence agency GRU.
The hacking group used previously disclosed vulnerabilities to target unpatched routers made by MicroTik and TP-Link, according to NCSC, the UK government’s cybersecurity arm, and Black Lotus Labs, the research arm of Lumen.
According to researchers, hackers have been able to spy on large numbers of people over the years by compromising routers, many of which were running outdated software, leaving them vulnerable to remote attacks without their owners knowing.
The NCSC said such operations are “likely to be opportunistic in nature as attackers cast a wide net to reach many potential victims before narrowing down targets of intelligence interest as the attack progresses.”
Russian hackers hacked routers and modified device settings to secretly route victims’ Internet requests to infrastructure operated by the hackers, according to researchers and government advisories. This allows hackers to redirect victims to spoofed websites they control and then steal passwords and tokens that allow hackers to log into victims’ online accounts without a two-factor authentication code.
Black Lotus Labs said Fancy Bear infected at least 18,000 victims in about 120 countries, including government departments, law enforcement agencies, and email providers across North Africa, Central America, and Southeast Asia.
Tech Crunch Event
San Francisco, California
|
October 13-15, 2026
Microsoft, which also revealed details of the campaign on Tuesday, said in a blog post that its researchers had identified more than 200 organizations and more than 5,000 consumer devices affected by these hacking activities, including at least three government agencies in Africa.
The FBI is expected to announce that it will take down several domains that hackers used in this campaign. Lumen said it was part of a coalition that included the FBI that disrupted the botnet and took it offline.
An FBI spokesperson did not respond to a request for comment before publication.