Russian state hackers are hijacking TP-Link and MicroTik routers to steal Outlook credentials, cybersecurity center warns — APT28 group targets DNS and redirects traffic to attacker-controlled servers Traffic is being redirected through attacker-controlled servers. Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. You are now subscribed Your newsletter sign-up was successful The UK National Cyber Security Centre (NCSC) on Tuesday published an advisory warning that Russian state hacking group APT28 has been exploiting vulnerable small office and home office (SOHO) routers since 2024 to overwrite their DHCP and DNS settings, redirecting downstream traffic through attacker-controlled DNS servers to harvest passwords and authentication tokens for web and email services. The NCSC assesses that APT28 is "almost certainly" the Russian Main Intelligence Directorate (GRU)'s 85th Main Special Service Centre, Military Intelligence Unit 26165. According to the advisory, the actor has been configuring virtual private servers to act as malicious DNS resolvers, then pointing compromised SOHO routers at them by rewriting the routers' DHCP DNS settings. Laptops, phones, and other downstream devices on the network inherit those settings automatically and begin sending lookups to the attacker-controlled infrastructure. Lookups for domains tied to targeted services, such as login pages, get pointed to further attacker-owned IPs that host adversary-in-the-middle infrastructure. Meanwhile, requests outside the targeting criteria are resolved to the legitimate addresses to avoid breaking the connection. Article continues belowOnce a victim connects through the attacker's infrastructure, APT28 attempts to capture passwords and OAuth or similar authentication tokens from both browser sessions and desktop applications. Targeted domains listed in the advisory include autodiscover-s.outlook.com, imap-mail.outlook.com, outlook.live.com, outlook.office.com, and outlook.office365.com. The TP-Link WR841N router is named by the NCSC as one of the models APT28 has been exploiting, likely using CVE-2023-50224, an unauthenticated information disclosure flaw that allows an attacker to retrieve credentials