The bottom line: Russia's military intelligence hackers hijacked at least 18,000 home and small office routers across 120+ countries. They didn't install malware. They just changed the DNS settings and redirected your internet traffic through their servers, silently stealing passwords, Microsoft Office authentication tokens, and emails. The attack bypassed multi-factor authentication entirely. On April 7, the FBI announced Operation Masquerade, a court-authorized takedown of compromised routers on U.S. soil.
Your Router Was the Weapon
On April 7, 2026, the UK's National Cyber Security Centre, the FBI, Microsoft, and researchers at Lumen's Black Lotus Labs dropped a coordinated bombshell: Russia's GRU (specifically Military Unit 26165, the same hackers behind the 2016 DNC breach) had been quietly taking over home routers worldwide for at least two years [1][2][3].
The group goes by many names. Fancy Bear. APT28. Forest Blizzard. Sednit. Whatever you call them, they're the GRU's 85th Main Special Service Centre, and they've been running one of the most efficient espionage campaigns in recent memory.
Here's the alarming part: they didn't need to put anything on your computer. They targeted the router sitting in your living room (the one you set up three years ago and never updated) and changed its DNS settings. That's it. From that moment on, when you typed "outlook.com," your router sent you to a Russian server instead.
How the Attack Worked
The technique is brutally simple, which is what makes it so effective.
Step 1: Find vulnerable routers. The GRU scanned the internet for TP-Link and MikroTik routers running outdated firmware or using default SNMP credentials. Specific models targeted include the TP-Link WR841N (CVE-2023-50224), Archer C5 and C7 series, WDR3500/3600/4300, and MR6400/MR3420 [3].
Step 2: Change the DNS settings. Using SNMP version 2 (which sends credentials in plaintext, no encryption), the hackers modified each router's DHCP and DNS configuration. They replaced the legitimate DNS servers with servers they controlled [3].
Step 3: Sit back and harvest. Every device on that home network (laptops, phones, tablets) now resolved domain names through Russian-controlled servers. When someone tried to reach Microsoft Outlook or Office 365, the GRU's DNS server directed them to a lookalike page that intercepted their login, captured the OAuth authentication token, and passed them through to the real site [1][2].
The victim noticed nothing. The page loaded normally. But the attackers now had their authentication token, the digital proof that says "this person already logged in and passed MFA." They could walk right into the victim's email, files, and cloud accounts without ever needing the password or the second factor.
The Numbers Are Staggering
According to Black Lotus Labs and Microsoft's joint findings [1][2]:
- 18,000+ networks compromised: routers across residential and small business environments
- 120+ countries affected: government departments, law enforcement, telecom providers, and energy companies across North Africa, Central America, Southeast Asia, Europe, and North America
- 200+ organizations specifically identified by Microsoft as targets, including at least three government organizations in Africa
- 5,000+ consumer devices caught in the operation
- 23+ U.S. states had compromised routers on American soil
The campaign ran from at least 2024 into 2026. The GRU described their approach as "opportunistic," cast a wide net, then filter the catch for high-value intelligence targets [3].
Operation Masquerade: The FBI Strikes Back
On April 7, the FBI's Boston Field Office announced Operation Masquerade, a court-authorized operation to neutralize compromised routers on U.S. soil [4].
"Operation Masquerade is the latest example of how we're defending our homeland from Russia's GRU, which weaponized routers owned by unsuspecting Americans," said Ted E. Docks, special agent in charge of the FBI's Boston Field Office.
The operation targeted routers compromised by GRU Unit 26165 across at least 23 states. Federal agents used court authorization to remotely access the compromised routers and undo the DNS changes, essentially kicking the Russians out of Americans' home networks.
This isn't the first time the FBI has done this. In 2024, the bureau ran a similar operation against a Chinese botnet that had hijacked hundreds of SOHO routers. The playbook is becoming familiar: get a court order, remotely access compromised devices, clean them up before the owners even know they were infected.
Why Your Router Is a Perfect Target
Home routers are the most neglected piece of cybersecurity infrastructure in existence. Think about it:
- You never update them. Router firmware updates require manual login to an admin panel most people have never seen. Manufacturers rarely push automatic updates.
- Default credentials everywhere. How many people changed their router's admin password from "admin/admin"? SNMP community strings default to "public" and "private," essentially leaving the door unlocked.
- No monitoring. Nobody checks their router logs. Most people wouldn't know how. The GRU could sit inside your router for months and you'd never notice.
- Every device trusts the router. Your laptop, phone, smart TV, security camera, they all ask the router "where is outlook.com?" and believe whatever answer they get.
Paul Chichester, the NCSC's director of operations, put it bluntly: "We strongly encourage organisations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice" [3].
What You Should Do Right Now
If you have a TP-Link or MikroTik router at home (or frankly, any consumer router) do these things today:
- Update your router firmware. Log into your router's admin panel (usually 192.168.1.1 or 192.168.0.1) and check for firmware updates. If your router hasn't been updated in over a year, it's almost certainly vulnerable.
- Change default credentials. Change the admin password. If your router uses SNMP, either disable it entirely or change the community string from the default.
- Check your DNS settings. In your router's network settings, make sure the DNS servers are set to something you recognize: your ISP's servers, or trusted alternatives like 1.1.1.1 (Cloudflare) or 9.9.9.9 (Quad9). If you see unfamiliar IP addresses, especially in the 77.83.197.x, 79.141.161.x, or 185.237.166.x ranges, your router may have been compromised [3].
- Disable remote management. Turn off any setting that allows your router to be managed from outside your home network. This closes the door the GRU walked through.
- Consider replacing old hardware. If your router is more than five years old and no longer receives firmware updates, it's a liability. A $60 router with current firmware is infinitely more secure than a $200 router from 2019 that hasn't been patched.
The Bigger Picture
This attack fits a pattern. Russia's GRU Unit 26165 is the same group that hacked the German parliament in 2015, targeted the Organisation for the Prohibition of Chemical Weapons in 2018, and most recently helped coordinate cyberattacks against Western logistics firms and tech companies supporting Ukraine [3].
But the router campaign shows how espionage has evolved. No zero-day exploits. No sophisticated malware. Just default passwords on consumer hardware that nobody bothers to secure, the same kind of weak-link vulnerability that drives so many supply chain attacks. The GRU built a surveillance network out of the routers sitting in people's kitchens.
And here's the part that should keep you up at night: if the GRU did this, other intelligence agencies almost certainly have too. The NSA, China's MSS, Israel's Unit 8200, they all know about the same vulnerabilities in the same routers. The difference is whether anyone's caught them yet.
Your router is a surveillance device. It always has been. The question is who's listening.
References
- TechCrunch: Russian government hackers broke into thousands of home routers to steal passwords (April 7, 2026)
- The Record: UK exposes Russian cyber unit hacking home routers to hijack internet traffic (April 7, 2026)
- UK NCSC: APT28 exploit routers to enable DNS hijacking operations (April 7, 2026)
- WJAR/NBC: FBI Boston neutralizes U.S. portion of hacked routers by Russia in Operation Masquerade (April 7, 2026)
- Infosecurity Magazine: Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns (April 7, 2026)
Published: April 8, 2026