[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fk8SO28mT6yTRA-88v9elE4d2VOrW4rKNCkLqwLt3jtc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"0d2dd537-a420-4e39-93a4-097979b724b2","state-sponsored-dns-hijacking-exploits-router-misconfigurations","6954ea14-7617-4eda-a2e2-802374a68f3a","State-Sponsored DNS Hijacking Exploits Router Misconfigurations","Russian GRU\u002FAPT28 threat actors successfully compromised thousands of routers across 23+ US states by exploiting DNS configuration vulnerabilities, allowing them to redirect internet traffic and potentially intercept communications. This campaign demonstrates how attackers can weaponize poorly configured network infrastructure to conduct large-scale espionage operations against critical infrastructure. The FBI's coordinated response involved resetting compromised devices and restoring legitimate DNS settings, highlighting the importance of proper router hardening and monitoring.","**Immediate actions:**\n- Change default credentials on all routers and network devices to strong, unique passwords\n- Verify DNS server configurations and ensure they point to trusted, legitimate DNS providers\n- Apply latest firmware updates to all internet-facing routers and network appliances\n\n**Long-term improvements:**\n- Implement network segmentation to isolate critical infrastructure from internet-facing devices\n- Deploy centralized configuration management for all network devices with regular compliance checks\n- Establish monitoring systems to detect unauthorized DNS configuration changes\n\n**Detection measures:**\n- Monitor DNS query patterns for unusual traffic redirection or suspicious domain resolutions\n- Implement network traffic analysis to identify anomalous communication patterns",[12,13,14,15,16,17],"CIS Control 1.1","CIS Control 4.1","CIS Control 12.1","NIST CM-6","NIST CM-7","NIST SI-4","published","2026-04-10T22:09:21.38727+00:00","2026-04-10T22:09:21.272+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fx.com\u002FSentinelOne\u002Fstatus\u002F2042709883104170045","good-fbi-dismantles-gru-apt28-dns-hijacking-network-23-states-thousands-of-route-c8f06e","✅ GOOD\n- FBI dismantles GRU\u002FAPT28 DNS hijacking network — 23+ states, thousands of routers, criti...",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"993e8114-39e6-455e-9f63-e99184078da9","2026-04-11","morning","ThreatNoir Weekend Brief — April 11","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-11\u002Fthreatnoir-morning-brief-2026-04-11.mp3"]