Russian state-sponsored hackers, known as APT28, had their DNS hijacking network disrupted by the US, specifically the FBI, which intervened to sever connections between compromised US-based routers and the malicious network. The FBI's operation effectively unplugged the routers from APT28's control, mitigating the threat. This countermeasure underscores the shifting threat landscape, where state-aligned actors are increasingly involved in cyber operations, necessitating a distinct approach to cybersecurity. The involvement of APT28, a notorious group linked to Russian intelligence, highlights the geopolitical aspect of cyber threats, which demands a different response strategy than traditional cybercrime. The FBI's actions demonstrate a proactive stance against state-sponsored hacking, acknowledging the evolving nature of cyber threats1. This development matters to cybersecurity practitioners, as it signifies a need to adapt their threat models to account for state-aligned activity, requiring a more nuanced and comprehensive approach to security.
US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers
⚡ High Priority
Why This Matters
State-aligned activity involving FBI shifts the threat model from criminal to geopolitical — different playbook required.
References
- Infosecurity Magazine. (2026, April 8). US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers. Infosecurity Magazine. https://www.infosecurity-magazine.com/news/us-thwarts-dns-hijacking-network/
Original Source
Infosecurity Magazine
Read original →