#APT28
4 stories taggedAPT28.

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details
Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

Hotel Wi-Fi hijack campaign quietly harvests Microsoft 365 logins from business travellers
A cluster with overlaps to Russia-linked APT28 activity is tampering with DNS on hotel and conference Wi-Fi gateways to funnel guests into fake Microsoft login pages, ReliaQuest reports.

Russian FSB hackers are quietly hijacking routers at hospitals, power firms and banks, nine countries warn
A joint advisory from the US, UK, Australia and six allies names FSB Centre 16 as the group scanning the internet for routers with weak passwords and old Cisco flaws.

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers
Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.