APT28's Forest Blizzard Harvests Credentials Through Compromised SOHO Routers
Russia's APT28 has been silently intercepting internet traffic at government and critical infrastructure targets worldwide since at least 2024, exploiting old bugs in SOHO routers and tweaking a single DNS setting to steal credentials.