APT28 Exploits SOHO Routers for DNS Hijacking and Token Theft
APT28, a Russia-linked threat actor, is actively exploiting vulnerabilities in older SOHO routers to conduct a global DNS hijacking campaign. This operation aims to intercept and steal Microsoft Office tokens, leveraging known router vulnerabilities. Security teams should prioritize patching affected router models and monitor network traffic for signs of DNS manipulation to mitigate potential breaches.