Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign
2026-04-08T20:51:42Z•cc32e2166a14e21ba8187c498d98e0979e41cc9f92b8b2c16a5c6c7b3fbd6b88
GRUai injectionclickfixcrypto theftdata exfiltrationdns hijackingfast exploitationforest blizzardgrafanaghostmedusa ransomwaremicrosoft account theft','cloudflare','emdash cms','wordpress','missile-alert luremonero miningnodejs malwareoperation masqueradephishingprompt injectionprotocol-relative url bypassqr-code phishingransomwareref1695router compromisestorm-1175torzero-day exploitation
What happened
Multiple high-impact threats and vulnerabilities reported: US authorities disrupted a Russian GRU campaign (Operation Masquerade / Forest Blizzard) that hijacked home/business routers via DNS manipulation to conduct espionage and credential theft; Storm-1175 is rapidly weaponizing disclosed flaws to deploy Medusa ransomware against healthcare and education (exploitation within 24 hours); a ClickFix campaign uses fake CAPTCHAs to deliver Tor-backed Node.js malware that drains crypto wallets; REF1695 is distributing Monero-mining malware via fake non‑profit installers; GrafanaGhost is a critical
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- cc32e2166a14e21ba8187c498d98e0979e41cc9f92b8b2c16a5c6c7b3fbd6b88
- Enrichment time
- 2026-04-08T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.