
MikroTik
Latvian router maker whose devices recur in botnet and DNS-hijacking cybersecurity incidents worldwide.
NCSC named MikroTik routers, alongside TP-Link consumer hardware, in its 7 April 2026 advisory on APT28's SOHO router DNS-hijacking campaign, a technique that has compromised home-office devices since 2024 to intercept Microsoft 365 logins.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Are MikroTik routers being actively targeted by Russian military intelligence?
Timeline for MikroTik
Mentioned in: Hotel WiFi steers guests to fake logins
Cybersecurity: Threats and DefencesMentioned in: UAT-8616 keeps Cisco SD-WAN under fire
Cybersecurity: Threats and DefencesMentioned in: FIRESTARTER implant survives every Cisco firewall patch
Cybersecurity: Threats and DefencesMentioned in: GRU hijacks home routers for M365 logins
Cybersecurity: Threats and DefencesBackground
MikroTik is a Latvian networking equipment company, founded in 1996, that produces networking hardware and its own RouterOS operating system. Its products are popular in small business and ISP environments, and are widely deployed as home-office routers in Europe, making it a common European alternative to Asian consumer networking hardware.
For organisations with European remote-working staff, MikroTik's prevalence means the April 2026 APT28 campaign affects a significant subset of home-office deployments, since the same DNS-hijacking technique that targets cheaper consumer routers also reaches MikroTik's more capable hardware.
Its routers feature in a GRU campaign
Multiple MikroTik router models were identified in the NCSC advisory of 7 April 2026 as hardware compromised by APT28, GRU Unit 26165, in its SOHO router DNS hijacking campaign targeting Microsoft 365 credentials. The campaign has run since 2024, silently rerouting sign-in pages to a GRU-controlled server before traffic ever reaches a corporate perimeter, which is why corporate monitoring alone cannot catch it.
MikroTik devices were targeted alongside TP-Link WR841N and other consumer routers, and NCSC's recommended mitigations, firmware update, changed admin credentials, an admin interface exposure audit, apply to MikroTik hardware exactly as they do to TP-Link's. RouterOS's more advanced feature set compared with typical consumer routers, offering more powerful DNS and routing manipulation once compromised, may explain why MikroTik equipment was swept into the same campaign as cheaper consumer brands.