• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

US & Partner Intelligence Agencies Warn of Russian Cyber Exploits Through Faulty Routers

  • SOFX Staff Writer
  • February 28, 2024
(Shutterstock / Photo Contributor Dmytro Tyshchenko)
Share on FacebookShare on TwitterLinkedIn

The Federal Bureau of Investigation (FBI), National Security Agency (NSA), US Cyber Command, and international partners have issued a critical cybersecurity advisory. This alert brings to light the sophisticated cyber operations conducted by Russian state-sponsored actors, notably APT28, also known as Fancy Bear and Forest Blizzard, through compromised Ubiquiti EdgeRouters. The advisory aims to provide a comprehensive understanding of the tactics, techniques, and procedures (TTPs) employed, along with mitigation strategies to counter these threats effectively.

The Threat Landscape

APT28, identified with the Russian General Staff Main Intelligence Directorate (GRU), has exploited vulnerabilities in Ubiquiti EdgeRouters to facilitate a range of malicious activities. These activities include credential harvesting, network traffic proxying, and hosting spear-phishing campaigns. Targets span across various sectors, including academic and research institutions, embassies, defense contractors, and political organizations globally.

Ubiquiti EdgeRouters, favored for their user-friendly Linux-based operating system, have become a prime target due to inherent security weaknesses. Many devices are shipped with default credentials and lack adequate firewall protections, making them susceptible to exploitation. Furthermore, these routers do not automatically update their firmware, posing a significant security risk if not manually updated by the user.

Mitigation Recommendations

The advisory outlines several critical steps for mitigating the threat posed by compromised routers:

  • Hardware Factory Reset: This action is recommended to eliminate any malicious configurations and files that may be present on the device.
  • Firmware Update: Upgrading to the latest firmware version is crucial for fixing vulnerabilities that could be exploited by cyber actors.
  • Changing Default Credentials: Users are advised to change any default usernames and passwords to prevent unauthorized access.
  • Implementing Firewall Rules: Strategic firewall rules should be applied on WAN-side interfaces to block unsolicited inbound traffic and mitigate the risk of external attacks.

International Response and Collaboration

The joint advisory is a result of collaboration between US intelligence agencies and international partners from Belgium, Brazil, France, Germany, Latvia, Lithuania, Norway, Poland, South Korea, and the United Kingdom. This collective effort underscores the global nature of cyber threats and the importance of international cooperation in addressing these challenges.

Read The Full Report

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Trump Threatens to Obliterate Iran’s Oil and Water Infrastructure

Videos From Iraq Show What It’s Like to Be on the Receiving End of an A-10 Warthog Strafing Run

by SOFX Staff Writer
March 31, 2026
0

A series of videos emerging from Iraq over the past several days captures what it looks like, and sounds like,...

Video Captures Navy Super Hornet Narrowly Dodging Iranian Missile

Video Captures Navy Super Hornet Narrowly Dodging Iranian Missile

by SOFX Staff Writer
March 27, 2026
0

A U.S. Navy F/A-18 Super Hornet narrowly escaped an Iranian man-portable air-defense system (MANPADS) missile while conducting a strafing run...

Rangers and SEALs Join Thousands of Paratroopers in Middle East Buildup

Rangers and SEALs Join Thousands of Paratroopers in Middle East Buildup

by SOFX Staff Writer
March 31, 2026
0

Several hundred U.S. Special Operations forces, including Army Rangers and Navy SEALs, have arrived in the Middle East, The New...

New Opioid 10 Times More Potent Than Fentanyl Linked to Fatal Overdoses in the U.S.

New Opioid 10 Times More Potent Than Fentanyl Linked to Fatal Overdoses in the U.S.

by SOFX Staff Writer
April 1, 2026
0

A newly emerging synthetic opioid is raising alarm among health officials and law enforcement across parts of the United States,...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Subsea Sabotage? Underwater Cables Damaged in Red Sea Amid Houthi Threats

Subsea Sabotage? Underwater Cables Damaged in Red Sea Amid Houthi Threats

Navalny’s Foundation Head Claims Jailed Opposition Leader Was Nearing Prisoner Swap Release

Navalny's Foundation Head Claims Jailed Opposition Leader Was Nearing Prisoner Swap Release

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz