The FBI and Justice Department said they disrupted multiple Russian GRU operations that hijacked small office/home office routers to conceal espionage activity, proxy malicious traffic, and steal credentials. In one court-authorized action, Operation Dying Ember, agents remotely accessed hundreds of compromised Ubiquiti EdgeOS routers infected with Moobot, deleted malware and related files, and temporarily changed firewall rules to cut off APT28—also tracked as Fancy Bear, Sednit, and Forest Blizzard—without disrupting normal device use. Officials said the botnet had originally been built by cybercriminals abusing internet-exposed routers with default administrator passwords before being repurposed by Russia’s GRU Unit 26165.
U.S. authorities later said a related GRU campaign also compromised SOHO routers, including TP-Link devices, to alter DNS settings and conduct adversary-in-the-middle attacks against TLS sessions, including Outlook traffic, in operations affecting government, IT, telecommunications, and energy targets. In Operation Masquerade, the FBI sent commands to infected routers to collect forensic data and reset malicious DNS configurations, removing Russian access from the devices. Microsoft and U.S. agencies linked the activity to APT28 and warned that router compromises can enable traffic redirection, credential theft, malware delivery, and denial-of-service attacks, urging organizations to patch firmware, verify DNS settings, disable unnecessary remote management, and replace end-of-life hardware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Sekoia reported that APT28/Fancy Bear had shifted heavily to compromised SOHO routers, consumer edge devices, and cloud services, with a peak in December 2025 of more than 18,000 IP addresses across 120 countries communicating with actor-controlled servers. The report also described about 200 affected organizations, roughly 5,000 consumer devices, DNS interception activity against services such as Microsoft 365, and tooling including LameHug and the BeardShell backdoor.
The U.S. Justice Department announced that the FBI's Operation Masquerade disrupted a GRU campaign that hijacked SOHO routers, including TP-Link devices, to alter DNS settings and steal data. The FBI sent commands to compromised routers to collect forensic information and reset malicious DNS configurations, cutting off Russian access.
The NSA published a press release supporting the FBI in highlighting Russian GRU threats against routers, underscoring the national security risk posed by the campaign. The statement accompanied broader public disclosure of the activity.
Microsoft said the GRU-linked actor APT28/Fancy Bear/Forest Blizzard had been compromising routers since at least August 2025 to enable large-scale DNS hijacking and adversary-in-the-middle attacks. The company observed data theft affecting sectors including government, IT, telecommunications, and energy.
U.S. prosecutors said a separate GRU campaign abusing hacked SOHO routers to redirect DNS traffic and steal sensitive data had been underway since at least 2024. The activity targeted victims including governments and critical infrastructure operators.
U.S. authorities publicly warned that Russian and Chinese state-backed actors were compromising small office/home office routers, including Ubiquiti devices, to support covert operations. The warning followed the February botnet disruption and highlighted ongoing router-focused threats.
In the court-authorized Operation Dying Ember, the FBI remotely accessed hundreds of compromised Ubiquiti routers used by GRU Unit 26165 (APT28/Fancy Bear), deleted Moobot and related malicious files, and temporarily changed firewall rules to block Russian access. The Justice Department announced the disruption on February 15, 2024.
Unrelated cybercriminals initially created a botnet by infecting Internet-exposed Ubiquiti EdgeOS SOHO routers running with default administrator passwords using Moobot malware. This botnet was later repurposed by Russia's GRU for espionage operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
freebuf.com
Open sourcecybersecuritydive.com
Open sourcensa.gov
Open sourcearstechnica.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.