APT28 exploit routers to enable DNS hijacking operations
2026-04-10T08:52:23Z•d809d05537542f42881070093b3a0324134343e2387a025a26c4e0a9a0611bc2
APT28Cisco Catalyst SD-WANCitrix NetScaler ADCCitrix NetScaler GatewayDNS hijackingF5 BIG-IP APMMiddle East conflictNCSC guidanceedge deviceshacktivist activitymessaging app targetingremote code executionroutersthreat intelligencevulnerability advisory
What happened
The UK NCSC published multiple high‑priority advisories: Russian actor APT28 is exploiting vulnerable routers to perform DNS hijacking for man‑in‑the‑middle attacks and credential/token theft; organisations are urged to investigate and secure edge devices. The NCSC also warns of an unauthenticated remote‑code‑execution vulnerability affecting F5 BIG‑IP Access Policy Manager, multiple recently disclosed Citrix NetScaler ADC/Gateway vulnerabilities, and active exploitation of Cisco Catalyst SD‑WAN — all requiring immediate mitigation and compromise investigation. Additional guidance covers risks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- uk_ncsc_all_rss
- Record identifier
- d809d05537542f42881070093b3a0324134343e2387a025a26c4e0a9a0611bc2
- Enrichment time
- 2026-04-10T08:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.