Russian Hackers Exploit Routers for Espionage, UK Agency Warns
Russian Hackers Exploit Routers for Espionage, UK Agency Warns

The UK's National Cyber Security Centre (NCSC) has warned that Russian hackers are exploiting commonly sold internet routers to harvest information for espionage purposes. The attacks, believed to be carried out by the group APT28 (also known as Fancy Bear), are described as opportunistic, targeting a wide pool of victims before filtering for those of intelligence value.

Alan Woodward, a professor at the University of Surrey, explained that the hack could allow attackers to obtain users' credentials, redirect them to fake websites, and potentially access other devices on their home network, such as phones and PCs. He stressed the importance of staying alert for unusual activity, as many routers are forgotten and become weak points.

The NCSC noted that the group is 'almost certainly' linked to Russian intelligence services. APT28 was also behind the 2015 cyber-attack on the German parliament, where large amounts of data were stolen. Woodward added that while the group is suspected to work for the Russian state, nation-state attacks are often conducted through criminal groups, making definitive attribution difficult.

The warning follows a pattern of cyber-actors targeting edge devices like routers and security cameras. The US recently banned the sale of consumer-grade routers made outside the country, citing national security risks. However, privacy experts argue that the ban does not address vulnerabilities in existing routers, many of which are outdated and no longer receiving security updates.

Woodward advised small businesses and individuals to keep their routers updated and watch for unusual network activity. He cited the 2016 Bangladesh bank heist, where hackers used a cheap, secondhand router to access the central bank's network and steal $80 million, as a cautionary example.