News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Apr 8, 2026 at 11:00 Big Tech Stable Warm

Thousands of consumer routers hacked by Russia's military

End-of-life routers in homes and small offices hacked in 120 countries.

Signal weather

Stable

The story has moved beyond the first headline and now acts as a reliable context anchor.

By Dan Goodin Original source
Thousands of consumer routers hacked by Russia's military

The Russian military is once again hacking home and small office routers in widespread operations that send unwitting users to sites that harvest passwords and credential tokens for use in espionage campaigns, researchers said Tuesday. An estimated 18,000 to 40,000 consumer routers, mostly those made by MikroTik and TP-Link, located in 120 countries, were wrangled into infrastructure belonging to APT28, an advanced threat group that’s part of Russia’s military intelligence agency known as the GRU, researchers from Lumen Technologies' Black Lotus Labs said. The threat group has operated for at least two decades and is behind dozens of high-profile hacks targeting governments worldwide. APT28 is also tracked under names including Pawn Storm, Sofacy Group, Sednit, Tsar Team, Forest Blizzard, and STRONTIUM. Technical sophistication, tried-and-true techniques A small number of routers were used as proxies to connect to a much larger number of other routers belonging to foreign ministries, law enforcement, and government agencies that APT28 wanted to spy on. The group then used its control of routers to change DNS lookups for select websites, including, Microsoft said, domains for the company’s 365 service. Read full article Comments

Stay on the signal

Follow Thousands of consumer routers hacked by Russia's military

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

This story is still moving and pulling follow-up coverage.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Consumer Routers, and Countries, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

May 29, 2026 at 22:58 Ars Technica

Proposed new US funding rules: We can cancel any grant at any time

Peer review now optional, political staff would screen grants for forbidden topics.

May 29, 2026 at 21:17 Ars Technica

Kenyan court blocks Trump admin from dumping Ebola-exposed Americans there

The US has previously built specialized facilities just for this purpose.

May 29, 2026 at 18:46 Ars Technica

Botnet of more than 17 million devices dismantled

The botnet was reportedly tied to a Russia-based residential proxy network.

May 29, 2026 at 18:35 Ars Technica

Analysis of Texas measles outbreak shows just how dangerous virus is

About 1 in 5 cases were hospitalized and most of those developed complications.

May 29, 2026 at 18:21 Ars Technica

House of the Dragon S3 trailer revels in dragons, fire, and blood

"The crown is a weight that crushes. You'll do things that spell death for all involved."

Apr 8, 2026 at 11:00 Ars Technica

Thousands of consumer routers hacked by Russia's military

End-of-life routers in homes and small offices hacked in 120 countries.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

1

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page