Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’
2026-04-09T20:51:45Z•7305b065d64bbd50227739162b1e3c9ddc8b9b1ebf88c44f0b5dfc2743f5fb83
AI vulnerability scanningAPT28BitterCVE-2026-35616Forest BlizzardFortiClient EMSFortinetGRUGrafanaGhostICSIranian hackersMENAOperation MasqueradeProSpyProject GlasswingSCADAcredential theftcybercrime losses','IC3 report','fraud hunting','stalkerware','penergy sectorhack-for-hirejournalistsprompt injectionrouter hijackingwater sectorzero-day
What happened
Multiple high-impact cyber incidents and developments: the FBI dismantled a Russia-linked GRU campaign (APT28/Forest Blizzard) that hijacked ~18,000 routers in “Operation Masquerade,” enabling credential and token theft and lateral propagation beyond home/edge devices; a hack-for-hire spyware campaign (including suspected Indian-linked group Bitter and ProSpy) targeted journalists across the Middle East and North Africa; U.S. authorities warned of Iranian government-linked disruptive attacks against energy and water infrastructure (PLC/SCADA targets); Fortinet customers face an actively-exploi
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- 7305b065d64bbd50227739162b1e3c9ddc8b9b1ebf88c44f0b5dfc2743f5fb83
- Enrichment time
- 2026-04-09T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.