DNS hijacking
-
Russian military hackers target thousands of consumer routers, researchers say
Russian military-linked hackers used tens of thousands of consumer routers in 120 countries to reroute traffic to credential-harvesting sites, researchers said. The campaign targeted older MikroTik and TP-Link devices and used DNS changes to intercept connections.
-
APT28 linked to router hijacking campaign that affected 200 organizations
APT28 has been linked to a campaign that hijacked insecure routers to redirect DNS traffic and steal credentials. The operation affected more than 200 organizations and 5,000 consumer devices, according to Microsoft.
-
China-linked PlushDaemon hijacks software updates with new EdgeStepper implant, ESET says
ESET researchers say a China-linked group called PlushDaemon is hijacking software-update traffic using an EdgeStepper network implant that redirects update domains to attacker servers and delivers a chain of malware including LittleDaemon, DaemonicLogistics and the SlowStepper backdoor.



