SecPod

Learn Search

Search across all Learn content

← Back to Security Research
APT28 router security risk – weaponizing routers to deploy PRISMEX malwar

APT28 in 2026: Weaponizing Routers and Deploying PRISMEX Across Global Targets

The Russian state-linked threat actor APT28 (also known as Forest Blizzard and Pawn Storm) has intensified its cyber operations through two major campaigns: a large-scale DNS hijacking operation targeting SOHO routers and a spear-phishing campaign deploying the PRISMEX malware suite.

Apr 12, 2026By Rakshitha4 min read

About APT 28 router security risks

The Russian state-linked threat actor APT28 (also known as Forest Blizzard and Pawn Storm) has intensified its cyber operations through two major campaigns: a large-scale DNS hijacking operation targeting SOHO routers and a spear-phishing campaign deploying the PRISMEX malware suite.

These campaigns demonstrate a shift toward multi-layered attack strategies, combining infrastructure-level compromise with endpoint exploitation to enable persistent espionage, credential harvesting, and potential disruption of critical systems.

APT 28 campaign impact

  • APT28 conducted a global DNS hijacking campaign (FrostArmada) by compromising MikroTik and TP-Link routers.
  • The attackers modified DNS settings to redirect traffic and perform Adversary-in-the-Middle (AitM) attacks.
  • Over 18,000 IPs across 120+ countries were observed communicating with attacker infrastructure.
  • A second campaign deployed PRISMEX malware via spear-phishing, targeting Ukraine and allied sectors.
  • Rapid exploitation of zero-day vulnerabilities CVE-2026-21509 and CVE-2026-21513 enabled stealthy payload execution.
  • The campaigns highlight a dual objective: intelligence gathering and potential operational disruption.

APT 28: Campaign background

FrostArmada – DNS Hijacking Campaign

The FrostArmada campaign involved compromising vulnerable SOHO routers and reconfiguring them to use attacker-controlled DNS servers.

  • DNS traffic was redirected to malicious infrastructure.
  • Users attempting to access legitimate services were silently redirected.
  • AitM nodes intercepted authentication credentials without user interaction.

This operation was partially disrupted through Operation Masquerade, a coordinated effort involving law enforcement agencies.

PRISMEX Malware Campaign

Parallel to infrastructure attacks, APT28 launched a spear-phishing campaign delivering the PRISMEX malware suite.

Key techniques:

  • Steganography (payloads hidden in images)
  • COM hijacking for persistence
  • Abuse of legitimate cloud services for command-and-control

Targets included:

  • Government agencies
  • Defense and logistics sectors
  • NATO-aligned organizations

Vulnerabilities exploited by APT 28

CVE-2023-50224:

  1. Vulnerability: Improper Authentication Information Disclosure Vulnerability
  2. CVSS Score: 6.5
  3. EPSS Score: 1.49%
  4. Affected Products: TP-Link TL-WR841N routers

CVE-2026-21509:

  1. Vulnerability: Security Feature Bypass Vulnerability
  2. CVSS Score: 7.8
  3. EPSS Score: 7.50%
  4. Affected Products: Microsoft Office

CVE-2026-21513:

  1. Vulnerability: Security Feature Bypass Vulnerability27.97%
  2. CVSS Score: 27.97%
  3. EPSS Score: 8.8
  4. Affected Products: Microsoft Windows

APT 28 Tactics and Techniques

  • TA0002 – Execution: The vulnerabilities enable attackers to execute malicious code or payloads on the affected systems, including via malicious .LNK files and scripts.
  • TA0008 – Lateral Movement: Compromised routers and endpoints can be leveraged to pivot within the network, allowing attackers to expand access to additional systems.
  • TA0006 – Credential Access: DNS hijacking and AitM techniques allow attackers to intercept and steal authentication credentials, including passwords and OAuth tokens.
  • TA0001 – Initial Access: Attackers gain initial access through exploitation of vulnerable edge devices and spear-phishing campaigns delivering malicious files.
  • T1210 – Exploitation of Remote Services: Exploitation of vulnerabilities such as CVE-2023-50224 to gain unauthorized access to routers.
  • T1566 – Phishing: Spear-phishing emails used to deliver PRISMEX malware payloads.
  • T1557 – Adversary-in-the-Middle: DNS hijacking redirects traffic to attacker-controlled infrastructure for credential interception.
  • T1204 – User Execution: Users unknowingly execute malicious documents or shortcut (.LNK) files.
  • T1546 – Event Triggered Execution: Persistence achieved via COM hijacking techniques.

Visual Attack Flow

DNS Hijacking Attack Flow

plaintext
[User Request] -> [Compromised Router] -> [Modified DNS Settings] -> [Malicious DNS Server] -> [AitM Node] -> [Credential Harvesting & Exfiltration]

PRISMEX Infection Flow

plaintext
[Spear-Phishing Email] -> [Malicious Document / LNK File] -> [CVE-2026-21509 Trigger] -> [CVE-2026-21513 Execution] -> [PRISMEX Deployment] -> [Persistence + C2 Communication]

Indicators of Compromise (IOCs)

Network Indicators

  • Suspicious DNS requests routed to unknown or unauthorized DNS resolvers
  • DNS queries resolving legitimate domains (e.g., email/login portals) to unexpected or attacker-controlled IP addresses
  • Traffic redirection to Attacker-in-the-Middle (AitM) infrastructure
  • Communication with known malicious IPs:
    • 64.120.31[.]96 (AitM node observed since May 2025)
    • 79.141.160[.]78 (Global DNS/AitM node supporting DoT activity)

Domain Indicators

  • wellnesscaremed[.]com (linked to exploitation chain activity)

Host-Based Indicators

  • Execution of suspicious .LNK files from untrusted sources
  • Presence of malicious Microsoft Office documents with embedded macros (PRISMEX loaders)
  • Unusual use of JavaScript APIs:
    • util.readFileIntoStream()
    • RSS.addFeed()

Mitigation & Recommendations

Mitigation for CVE-2023-50224 (Router Exploitation)

  • Update firmware on TP-Link and MikroTik routers to the latest versions.
  • Disable remote administration unless explicitly required.
  • Change default credentials and enforce strong authentication.
  • Monitor DNS settings for unauthorized changes.
  • Segment network devices to limit lateral movement.

Mitigation for CVE-2026-21509 & CVE-2026-21513

  • Apply latest Windows security updates immediately.
  • Block or restrict execution of .LNK files from untrusted sources.
  • Disable macros in Microsoft Office by default.
  • Use endpoint detection tools to monitor suspicious process execution.
  • Inspect outbound connections to detect unusual C2 communication.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026