The FBI, the Department of Justice, and the National Security Agency have jointly warned that Russian military intelligence operatives are compromising home and small-business routers across the globe, using hijacked DNS settings to intercept sensitive traffic from military, government, and critical-infrastructure targets. The DOJ and FBI carried out a court-authorized operation to dismantle the U.S. portion of a compromised router network attributed to GRU Unit 26165, the hacking group widely tracked as APT28. The campaign exploited a known vulnerability in widely sold TP-Link routers, and the agencies say the threat extends well beyond the devices already seized.
Why the GRU’s router hijacking campaign demands attention right now
Most people treat a home router like a light switch: plug it in once and forget it. That neglect is exactly what GRU Unit 26165 has been counting on. By tampering with the DNS resolver settings on small office and home office (SOHO) routers, the unit redirected web traffic through servers it controlled, enabling adversary-in-the-middle interception of login credentials, email contents, and other data flowing to and from targeted organizations. The technique works silently; a compromised router looks and feels normal to its owner while quietly funneling selected traffic to Russian intelligence infrastructure.
The Justice Department disruption neutralized the U.S. segment of that network, but it did not eliminate the underlying vulnerability or the operators behind it. GRU cyber units have historically adapted quickly after public exposure, shifting tooling and infrastructure within months. A partial takedown of the resolver network is likely to push APT28 toward exploiting router firmware from vendors that have not yet drawn the same scrutiny. Security teams should expect a rise in exploitation attempts against previously unaffected brands and models as the group rebuilds its collection platform.
FBI, DOJ, and NSA evidence tying the campaign to GRU Unit 26165
The FBI’s Internet Crime Complaint Center published Alert Number I-040726-PSA, a public advisory explicitly naming Russian GRU cyber actors as the operators behind the router exploitation campaign. The alert specifies that the attackers used DNS manipulation to steal sensitive information from targets in the military, government, and critical-infrastructure sectors worldwide. The NSA co-sealed that same advisory, adding its own intelligence assessment to the FBI’s findings.
Separately, the U.S. Attorney’s Office for the Eastern District of Pennsylvania confirmed that the court order authorizing the technical operation was filed in that jurisdiction. The filings attribute the DNS hijacking network directly to GRU Unit 26165, the same group previously linked to the 2016 Democratic National Committee breach and other high-profile intrusions under the APT28 label. The operation involved replacing fraudulent DNS records on compromised routers with legitimate settings, effectively cutting off the GRU’s ability to redirect traffic through its own servers on those specific devices.
One concrete entry point the campaign relied on is CVE-2023-50224, a vulnerability cataloged in the National Vulnerability Database. That flaw enables information disclosure through an authentication bypass via spoofing on the TP-Link TL-WR841N, one of the best-selling consumer routers in the world. An attacker who exploits this bug can gain access to the router’s administrative interface without valid credentials, then alter DNS settings to route traffic wherever they choose.
What the agencies have not disclosed about the router campaign
Several gaps in the public record limit the full picture. No agency has released a verified count of how many routers were compromised in the United States or globally. The DOJ’s press materials describe the operation’s scope in general terms but redact specific technical indicators of compromise and the full list of domains the GRU used as fraudulent DNS destinations. Without those details, independent security researchers and affected router owners have limited ability to confirm whether their own devices were part of the network.
The public advisories also lack direct statements from network operators or internet service providers confirming observed malicious DNS activity on their infrastructure. That absence makes it harder to gauge how broadly the campaign touched ordinary internet users versus narrowly targeted government and military personnel. The FBI alert names military, government, and critical-infrastructure users as the primary victim categories, but the underlying SOHO routers sit in homes and small businesses where anyone on the same network could have had traffic intercepted.
A related open question is whether other router models beyond the TP-Link TL-WR841N were exploited using different vulnerabilities. The agencies’ guidance urges all SOHO router owners to update firmware, disable remote management features, and replace end-of-life devices that no longer receive security patches. That broad language suggests the threat is not confined to a single product line, even though CVE-2023-50224 is the only specific flaw named in the public record so far.
What router owners should do now
For individual users and small businesses, the most important response is to assume that any unpatched SOHO router could be at risk, regardless of brand. Owners should log into their router’s administration interface, confirm that the device is running the latest available firmware, and apply any pending updates immediately. If the router no longer receives vendor updates, replacing it with a supported model is the safest option.
Checking DNS settings is equally critical. Users should verify that the router is either obtaining DNS servers automatically from their internet provider or is configured to use a trusted resolver such as their ISP’s default or a reputable public DNS service. Any unfamiliar IP addresses listed as primary or secondary DNS servers, especially if manually entered, warrant further investigation and likely a full reset of the device.
Security agencies also recommend disabling remote administration features that allow management of the router from outside the local network. While convenient for troubleshooting, these interfaces are frequent targets for automated scanning and exploitation. Turning off Universal Plug and Play (UPnP) and restricting port-forwarding rules to only what is strictly necessary can further reduce the attack surface.
Where possible, router owners should change default administrator usernames and passwords to unique, complex credentials and enable multi-factor authentication if the device supports it. Using a separate guest network for visitors and untrusted devices, such as smart TVs or Internet of Things gadgets, can help isolate sensitive workstations from potentially compromised endpoints on the same router.
Small organizations that rely heavily on SOHO equipment should consider segmenting critical systems onto more robust, centrally managed networking gear. Even modest investments in business-grade firewalls or managed routers can provide better logging, intrusion detection, and patch management than consumer hardware, making it easier to spot and respond to anomalies like unexpected DNS changes.
How enterprises and governments should adapt
For larger enterprises and government agencies, the GRU router campaign underscores the need to treat employee home networks as part of the extended attack surface. Security teams should update remote-work policies to include minimum standards for home routers, such as requiring current firmware, non-default credentials, and disabled remote administration. Providing clear, step-by-step guidance or even subsidized hardware upgrades can reduce the risk that sensitive traffic traverses compromised devices.
Network defenders should also adjust monitoring to detect signs of DNS hijacking, including unexplained shifts in resolver IP addresses, anomalous DNS query patterns, or connections to known malicious infrastructure. While the DOJ operation disrupted specific GRU-controlled resolvers, the actors can and likely will stand up new servers; continuous monitoring is essential.
The joint actions described in the FBI alert and the Justice Department filings show that law enforcement and intelligence agencies are willing to take direct technical measures to remediate compromised civilian hardware when national-security interests are at stake. That approach raises complex questions about notification, privacy, and the limits of government access to privately owned devices, but it also demonstrates a recognition that state-backed cyber operations now routinely abuse the weakest links in everyday internet infrastructure.
Ultimately, the GRU’s exploitation of consumer routers is less a one-off campaign than a preview of how future espionage operations will blend traditional hacking with quiet manipulation of the hardware that underpins home and small-business connectivity. As long as routers remain cheap, poorly maintained, and rarely updated, they will continue to offer high-value footholds for sophisticated adversaries. Closing that gap will require sustained attention not only from governments and vendors, but from the millions of users whose networks those devices quietly protect-or expose-every day.
More from Morning Overview
*This article was researched with the help of AI, with human editors creating the final content.