Substrate
technology

International Probe Reveals Russian GRU Cyber Operations Targeting Vulnerable Routers Worldwide

An international investigation involving multiple countries has identified Russia's GRU cyber unit as responsible for exploiting vulnerable routers to steal sensitive government and military information. The operation, conducted by the group known as Fancy Bear, involved redirecting traffic through a network of DNS servers.

Euronews
1 source·Apr 8, 2:48 PM(27 days ago)·1m read
International Probe Reveals Russian GRU Cyber Operations Targeting Vulnerable Routers WorldwideEuronews
Audio version
Tap play to generate a narrated version.

An international investigation has uncovered cyber operations attributed to Russia's GRU military intelligence unit, specifically the 85th Main Special Service Centre (85th GTsSS). The group, also known as APT28, Fancy Bear, Tsar Team, and Forest Blizzard, exploited vulnerabilities in internet routers to access sensitive data from governments and military entities.

Ukraine's Security Service (SBU) participated in the probe, which involved intelligence and law enforcement services from multiple countries, including the US and UK.

The hackers compromised vulnerable routers and redirected traffic through a pre-deployed network of DNS servers to exfiltrate information. The operation targeted devices with inadequate security protections, allowing unauthorized access to networks.

Details The probe revealed cyber activities targeting governments and military organizations across multiple countries. The international collaboration aimed to identify the scope and methods of the cyber activities.

The use of DNS servers facilitated the redirection of data without immediate detection. Law enforcement agencies continue to analyze the extent of the compromises.

Context and Next Steps This operation occurs amid ongoing geopolitical tensions, particularly following Russia's invasion of Ukraine in 2022, which has heightened cyber threats between the involved nations.

The stakes involve national security, as stolen data could compromise intelligence operations or personal safety of individuals. Affected parties, including governments, face risks of further exploitation or retaliation. Following the investigation, authorities are expected to enhance router security protocols and share intelligence to prevent similar incidents.

International cooperation could potentially lead to coordinated responses. Monitoring for additional leaks and vulnerabilities remains ongoing.

Key Facts

GRU 85th GTsSS
cyber unit known as Fancy Bear and APT28
15 countries involved
in joint investigation including US, UK, Ukraine
Technique since 2024
DNS server redirection for data exfiltration
Targets included
governments, military, athletes like Williams sisters

Story Timeline

3 events
  1. 2024 onward

    Russian GRU cyber actors began using DNS redirection technique to steal data via vulnerable routers.

    1 sourceEuronews
  2. Recent

    International investigation involving 15 countries identified GRU's 85th GTsSS as responsible for the operations.

    1 sourceEuronews
  3. Post-investigation

    Hackers leaked personal information of athletes including Venus and Serena Williams.

    1 sourceEuronews

Potential Impact

  1. 01

    Increased international intelligence sharing could enhance detection of similar cyber threats.

  2. 02

    Governments may implement stricter router security measures to prevent future exploits.

  3. 03

    Geopolitical tensions between Russia and Western nations may escalate due to cyber attributions.

  4. 04

    Athletes and officials affected may pursue legal actions against data leaks.

Transparency Panel

Sources cross-referenced1
Confidence score70%
Synthesized bySubstrate AI
Word count250 words
PublishedApr 8, 2026, 2:48 PM
Bias signals removed3 across 2 outlets
Signal Breakdown
Loaded 2Editorializing 1

Related Stories

Major Publishers and Author Sue Meta for Using Copyrighted Works to Train Llama AIinsurancejournal.com
technology2 hrs agoUpdated

Major Publishers and Author Sue Meta for Using Copyrighted Works to Train Llama AI

Five major publishing houses and author Scott Turow filed a lawsuit against Meta in Manhattan federal court, accusing the company of pirating millions of copyrighted works to train its Llama AI models. The suit claims Meta CEO Mark Zuckerberg personally authorized the infringemen…

The Independent
fortune.com
The Washington Post
The Guardian
The Verge
+1
6 sources
Samsung Market Cap Tops $1 Trillion as Chip Stocks Rise Amid AI DemandSemafor
ai36 min agoDeveloping

Samsung Market Cap Tops $1 Trillion as Chip Stocks Rise Amid AI Demand

South Korea’s Samsung saw its market capitalization surpass $1 trillion as semiconductor demand rose. SK Hynix hit a record high and Alphabet advanced on a $200 billion Anthropic deal. AI firms DeepSeek and Anthropic pursue large valuations while analysts note sector momentum.

Cnbc
SQ
Semafor
3 sources
Brockman Testifies About 2017 Dispute with Musk Over OpenAI For-Profit Shiftjapantimes.co.jp
ai2 hrs agoUpdated

Brockman Testifies About 2017 Dispute with Musk Over OpenAI For-Profit Shift

OpenAI President Greg Brockman detailed a heated 2017 confrontation with Elon Musk during testimony in the federal trial Musk v. Altman. He described Musk storming around a table and grabbing a painting after rejecting shared control proposals. The lawsuit seeks $150 billion in d…

The New York Times
Wired
New York Post
BBC News
Business Insider
+4
10 sources