
APT28
Russian GRU military intelligence cyber unit; attributed with DNS-hijacking home routers to steal Microsoft 365 credentials.
NCSC attributed APT28 as 'almost certainly' GRU Unit 26165 on 7 April 2026 behind a campaign that had hijacked SOHO router DNS since 2024 to harvest Microsoft 365 credentials, a track record now complicated by a contested claim that the same group ran a July hotel-WiFi campaign.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Two Russian agencies now hijack routers by different methods; coordinated, or parallel operations?
Timeline for APT28
One firm hedged, heise online named APT28
Cybersecurity: Threats and DefencesMentioned in: Hotel WiFi steers guests to fake logins
Cybersecurity: Threats and DefencesNCSC names FSB Centre 16 over routers
Cybersecurity: Threats and DefencesTriple CVSS-10 Ubiquiti chain hits root
Cybersecurity: Threats and DefencesSixteen agencies put IOC extinction in print
Cybersecurity: Threats and DefencesBackground
APT28 (also tracked as Fancy Bear, Forest Blizzard, STRONTIUM, Sofacy and Pawn Storm) is the activity cluster that NCSC, CISA and the US Intelligence Community assess with high confidence as run by GRU Unit 26165, the 85th Main Special Service Centre of Russia's military intelligence directorate. The cluster and the unit are tracked as related but distinct entities: APT28 is the observed tradecraft, GRU Unit 26165 is the organisation behind it.
Active since at least 2008, APT28 specialises in credential theft, spear-phishing and the exploitation of edge devices and VPN appliances in service of intelligence collection rather than disruptive attacks. Its record includes the 2016 US election interference campaign (DNC and Podesta email exfiltration), the 2017 Macron campaign hack, the 2018 World Anti-Doping Agency compromise, the 2022 intrusions into Ukrainian government networks and the 2024 targeting of the German Bundestag.
A hotel-WiFi credential-theft campaign reported in July 2026 shows how quickly attribution can outrun the evidence: ReliaQuest, the firm that investigated the DNS-poisoning of hotel routers across the US, India and Saudi Arabia, held the access route at low-to-medium confidence and named no state actor, citing only overlap with an internal cluster it calls FrostArmada. heise online reported on 27 July that Russian state attackers, naming APT28 directly, ran the campaign. The two accounts diverge sharply, and nothing in this bundle resolves them, so APT28's role in the hotel-WiFi campaign remains a contested claim rather than an established fact.
Its DNS campaign gets its own attribution
NCSC published an attribution-backed advisory in April 2026 stating APT28 had, since 2024, compromised TP-Link WR841N and other SOHO routers via CVE-2023-50224 to hijack DNS resolution for Microsoft 365 endpoints, harvesting Outlook credentials and OAuth tokens through adversary-in-the-middle attacks; the advisory was co-issued with the FBI.
On 9 July, NCSC and 18 partner agencies published a further advisory attributing a separate SNMP-based router-hijacking campaign to Russia's FSB Centre 16, explicitly distinguishing it from APT28's own DNS campaign. Both target network-edge hardware, but APT28 operates under GRU military intelligence and hijacked DNS to harvest cloud credentials, while FSB Centre 16 operates under Russia's domestic security service and manipulated SNMP for router-level access, evidence Russia runs parallel, service-siloed edge-device operations rather than one unified campaign.