Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign

2026-04-08T20:51:42Zcc32e2166a14e21ba8187c498d98e0979e41cc9f92b8b2c16a5c6c7b3fbd6b88
GRUai injectionclickfixcrypto theftdata exfiltrationdns hijackingfast exploitationforest blizzardgrafanaghostmedusa ransomwaremicrosoft account theft','cloudflare','emdash cms','wordpress','missile-alert luremonero miningnodejs malwareoperation masqueradephishingprompt injectionprotocol-relative url bypassqr-code phishingransomwareref1695router compromisestorm-1175torzero-day exploitation

What happened

Multiple high-impact threats and vulnerabilities reported: US authorities disrupted a Russian GRU campaign (Operation Masquerade / Forest Blizzard) that hijacked home/business routers via DNS manipulation to conduct espionage and credential theft; Storm-1175 is rapidly weaponizing disclosed flaws to deploy Medusa ransomware against healthcare and education (exploitation within 24 hours); a ClickFix campaign uses fake CAPTCHAs to deliver Tor-backed Node.js malware that drains crypto wallets; REF1695 is distributing Monero-mining malware via fake non‑profit installers; GrafanaGhost is a critical

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
cc32e2166a14e21ba8187c498d98e0979e41cc9f92b8b2c16a5c6c7b3fbd6b88
Enrichment time
2026-04-08T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.