APT28 exploit routers to enable DNS hijacking operations

2026-04-10T08:52:23Zd809d05537542f42881070093b3a0324134343e2387a025a26c4e0a9a0611bc2
APT28Cisco Catalyst SD-WANCitrix NetScaler ADCCitrix NetScaler GatewayDNS hijackingF5 BIG-IP APMMiddle East conflictNCSC guidanceedge deviceshacktivist activitymessaging app targetingremote code executionroutersthreat intelligencevulnerability advisory

What happened

The UK NCSC published multiple high‑priority advisories: Russian actor APT28 is exploiting vulnerable routers to perform DNS hijacking for man‑in‑the‑middle attacks and credential/token theft; organisations are urged to investigate and secure edge devices. The NCSC also warns of an unauthenticated remote‑code‑execution vulnerability affecting F5 BIG‑IP Access Policy Manager, multiple recently disclosed Citrix NetScaler ADC/Gateway vulnerabilities, and active exploitation of Cisco Catalyst SD‑WAN — all requiring immediate mitigation and compromise investigation. Additional guidance covers risks

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
uk_ncsc_all_rss
Record identifier
d809d05537542f42881070093b3a0324134343e2387a025a26c4e0a9a0611bc2
Enrichment time
2026-04-10T08:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.