Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’

2026-04-09T20:51:45Z7305b065d64bbd50227739162b1e3c9ddc8b9b1ebf88c44f0b5dfc2743f5fb83
AI vulnerability scanningAPT28BitterCVE-2026-35616Forest BlizzardFortiClient EMSFortinetGRUGrafanaGhostICSIranian hackersMENAOperation MasqueradeProSpyProject GlasswingSCADAcredential theftcybercrime losses','IC3 report','fraud hunting','stalkerware','penergy sectorhack-for-hirejournalistsprompt injectionrouter hijackingwater sectorzero-day

What happened

Multiple high-impact cyber incidents and developments: the FBI dismantled a Russia-linked GRU campaign (APT28/Forest Blizzard) that hijacked ~18,000 routers in “Operation Masquerade,” enabling credential and token theft and lateral propagation beyond home/edge devices; a hack-for-hire spyware campaign (including suspected Indian-linked group Bitter and ProSpy) targeted journalists across the Middle East and North Africa; U.S. authorities warned of Iranian government-linked disruptive attacks against energy and water infrastructure (PLC/SCADA targets); Fortinet customers face an actively-exploi

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
7305b065d64bbd50227739162b1e3c9ddc8b9b1ebf88c44f0b5dfc2743f5fb83
Enrichment time
2026-04-09T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’ · Baitaphish