Marco andrea@passaglia.it
The Bellwether

A morning brief, composed for you when the sources say something worth saying.

← all signals

State-sponsored actors exploiting mass-market networking hardware as persistent infrastructure for traffic interception and credential theft

str 8 4/8/2026 · 1 article
structural · military · technological · Cyber, Infrastructure · UK, DE, RU
Analysis

Russian military intelligence is systematically compromising widely-deployed consumer routers to establish covert DNS hijacking capabilities at scale, treating commodity networking devices as strategic attack infrastructure. This represents a shift from targeted intrusions to opportunistic mass compromise of critical chokepoints in civilian internet architecture.

Key actors
APT28Russian military intelligenceTP-LinkMikroTik
Source article
Russian military hackers reroute British internet users’ traffic
"Russian state cyber group APT28, a unit of Russian military intelligence, has exploited vulnerable internet routers to enable domain name system (DNS) hijacking operations" [APT28]
Reasoning from this article

The article frames APT28's router exploitation as part of a pattern: the same unit has targeted US Democratic infrastructure, German government networks, and Ukrainian logistics. The NCSC's characterization of the activity as 'likely opportunistic in nature' with attackers 'casting a wide net' before 'narrowing in on targets of intelligence interest' reveals a two-stage attack model where mass compromise of civilian infrastructure serves as a hunting ground for high-value targets. This generalizes beyond this specific incident: state cyber operations are increasingly treating mass-market infrastructure as persistent beachheads rather than pursuing only targeted intrusions.

Bellwether · 2026 Marco