Skip to content
You can now search across every topic, entity and event.What's new
MikroTik
ProductLV

MikroTik

Latvian router maker whose devices recur in botnet and DNS-hijacking cybersecurity incidents worldwide.

NCSC named MikroTik routers, alongside TP-Link consumer hardware, in its 7 April 2026 advisory on APT28's SOHO router DNS-hijacking campaign, a technique that has compromised home-office devices since 2024 to intercept Microsoft 365 logins.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Are MikroTik routers being actively targeted by Russian military intelligence?

Timeline for MikroTik

#12 22 Jul
#4 14 May

Mentioned in: UAT-8616 keeps Cisco SD-WAN under fire

Cybersecurity: Threats and Defences
#1 7 Apr
View full timeline →

Background

MikroTik is a Latvian networking equipment company, founded in 1996, that produces networking hardware and its own RouterOS operating system. Its products are popular in small business and ISP environments, and are widely deployed as home-office routers in Europe, making it a common European alternative to Asian consumer networking hardware.

For organisations with European remote-working staff, MikroTik's prevalence means the April 2026 APT28 campaign affects a significant subset of home-office deployments, since the same DNS-hijacking technique that targets cheaper consumer routers also reaches MikroTik's more capable hardware.

Key Issues
Router exploitation

Its routers feature in a GRU campaign

Multiple MikroTik router models were identified in the NCSC advisory of 7 April 2026 as hardware compromised by APT28, GRU Unit 26165, in its SOHO router DNS hijacking campaign targeting Microsoft 365 credentials. The campaign has run since 2024, silently rerouting sign-in pages to a GRU-controlled server before traffic ever reaches a corporate perimeter, which is why corporate monitoring alone cannot catch it.

MikroTik devices were targeted alongside TP-Link WR841N and other consumer routers, and NCSC's recommended mitigations, firmware update, changed admin credentials, an admin interface exposure audit, apply to MikroTik hardware exactly as they do to TP-Link's. RouterOS's more advanced feature set compared with typical consumer routers, offering more powerful DNS and routing manipulation once compromised, may explain why MikroTik equipment was swept into the same campaign as cheaper consumer brands.

Common Questions
Are MikroTik routers safe to use after the APT28 warning?
NCSC's April 2026 advisory named MikroTik among the router models exploited by APT28. Mitigation is to update RouterOS to the latest firmware and change default admin credentials.Source: NCSC PSA260407
What is MikroTik?
MikroTik is a Latvian networking equipment manufacturer, founded in 1996, best known for its RouterOS operating system and the small-office and home routers it ships widely across Europe.Source: NCSC PSA260407
Why do MikroTik routers keep turning up in cybersecurity advisories?
MikroTik's routers are widely deployed in European homes, small offices and ISPs, so state and criminal hacking groups target them at scale. NCSC named MikroTik models among the routers APT28 hijacked for DNS-based Microsoft 365 credential theft in April 2026.Source: NCSC PSA260407
Did APT28 exploit a specific MikroTik vulnerability?
NCSC's April 2026 advisory did not cite a specific MikroTik CVE. The attack chain used the TP-Link WR841N flaw CVE-2023-50224 alongside several MikroTik models, pointing to weak configuration or credential reuse rather than one named MikroTik flaw.Source: NCSC PSA260407