[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkamIlgl4oS6GGxX9ou7puKUk0t2gCooIulNe_W19az8":3},{"article":4,"iocs":45,"watch_terms":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":25,"category":26,"article_tags":29},"6954ea14-7617-4eda-a2e2-802374a68f3a","✅ GOOD\n- FBI dismantles GRU\u002FAPT28 DNS hijacking network — 23+ states, thousands of routers, criti...","good-fbi-dismantles-gru-apt28-dns-hijacking-network-23-states-thousands-of-route-c8f06e","✅ GOOD\n- FBI dismantles GRU\u002FAPT28 DNS hijacking network — 23+ states, thousands of routers, critical infrastructure targets\n- Devices reset, DNS restored, ISPs notifying affected users","The FBI has successfully dismantled a DNS hijacking campaign attributed to Russia's GRU and APT28 threat group that compromised thousands of routers across 23+ US states and targeted critical infrastructure. The operation involved resetting affected devices and restoring legitimate DNS configurations, with ISPs now notifying impacted users. This represents a significant law enforcement action against a persistent state-sponsored cyber operation.","FBI dismantles GRU\u002FAPT28 DNS hijacking network affecting thousands of routers across 23+ US states.",null,"https:\u002F\u002Fx.com\u002FSentinelOne\u002Fstatus\u002F2042709883104170045","2026-04-10T21:02:42+00:00","2026-04-10T22:00:06.714733+00:00",9,[17,20,22],{"name":18,"type":19},"GRU (Russia)","threat_actor",{"name":21,"type":19},"APT28",{"name":23,"type":24},"DNS infrastructure","technology","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":25,"icon":11,"name":27,"slug":28},"Nation-state","nation-state",[30,35,40],{"category":31},{"id":32,"icon":11,"name":33,"slug":34},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":41},{"id":42,"icon":11,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46],{"type":47,"value":48,"context":49},"mitre_attack","T1589.002 (DNS Records)","DNS hijacking and redirection technique used in campaign",[]]