APT28 exploit routers to enable DNS hijacking operations

2026-04-08T20:52:19Zd70cf5fa3583e592a99a707a17c58e6c90c2c87491ca85ee5ebd39bf1f35e834
apt28big-ip apmcisco catalyst sd-wancitrix netscalercredential theftcspmcyber guidancedns hijackingdoseasmedge devicesf5 big-ipfrontier aihacktivistmessaging app targetingmiddle east conflict advisorymitmncscnetscaler adcnetscaler gatewayrcerouterssd-wan compromisevulnerability management

What happened

UK NCSC alerts (Jan–Apr 2026) covering multiple active and high-impact threats: Russian APT28 is exploiting vulnerable edge routers to perform DNS hijacking (enabling MitM, credential and token theft); agencies report active exploitation/compromise of Cisco Catalyst SD‑WAN; an unauthenticated remote‑code‑execution vulnerability affects F5 BIG‑IP APM (NCSC urges mitigation); and two recently disclosed vulnerabilities affect Citrix NetScaler ADC and Gateway (immediate action recommended). Additional guidance/alerts include messaging‑app targeted‑attack mitigations, warnings about pro‑Russia hack

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
uk_ncsc_all_rss
Record identifier
d70cf5fa3583e592a99a707a17c58e6c90c2c87491ca85ee5ebd39bf1f35e834
Enrichment time
2026-04-08T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · APT28 exploit routers to enable DNS hijacking operations · Baitaphish