Full Breakdown
U.S. Disrupts Russian Military-Controlled DNS Hijacking Network
4/8/2026, 4:50:42 AM
Overview of the Operation
On April 7, 2026, the U.S. Justice Department announced the disruption of a Domain Name System (DNS) hijacking network operated by Russia's Main Intelligence Directorate of the General Staff (GRU), specifically Military Unit 26165. This operation, termed "Operation Masquerade," was authorized by a court and involved collaboration with partners in 15 countries. The GRU utilized compromised routers to conduct espionage against various global targets, including military, government, and critical infrastructure sectors.
Mechanism of the Attack
The GRU's operations involved hijacking thousands of routers worldwide, allowing them to filter internet traffic and identify specific targets. Once identified, the hackers captured unencrypted network traffic, which included sensitive information such as passwords, authentication tokens, and emails. Brett Leatherman, assistant director of the FBI’s Cyber Division, emphasized the scale of the threat, stating that without intervention, the GRU would have continued intercepting encrypted traffic and stealing sensitive information.
International Response
The operation prompted advisories from officials in Germany and Britain, highlighting the widespread nature of the hacking campaign. The National Cyber Security Centre (NCSC) in the UK also released an advisory detailing how Russian cyber actors, particularly the group known as APT28, exploited vulnerabilities in commonly used routers for DNS hijacking. This advisory underscored the opportunistic nature of the attacks, which initially targeted a broad range of victims before narrowing in on those of intelligence interest.
Impact and Scope
Microsoft reported that the GRU's hacking operation affected over 200 organizations and approximately 5,000 consumer devices. The targeted entities included government agencies, law enforcement, and third-party email providers across various regions, including the U.S., Europe, Afghanistan, North Africa, Central America, and Southeast Asia. Lumen Technologies' Black Lotus Labs also noted that the operations primarily focused on government sectors.
Criticism & Opposition
While the Justice Department's actions were framed as necessary to combat an enduring threat from Russia's cyber program, the Russian Embassy in Washington did not respond to requests for comment regarding the operation. This silence raises questions about the potential for diplomatic repercussions and the ongoing tensions between the U.S. and Russia in the realm of cybersecurity.
Verbatim Quotes
- "GRU actors compromised routers in the U.S. and around the world, hijacking them to conduct espionage. Given the scale of this threat, sounding the alarm wasn't enough." — Brett Leatherman, Assistant Director, FBI’s Cyber Division
- "This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors." — Paul Chichester, NCSC Director of Operations
The disruption of the GRU's DNS hijacking network marks a significant step in addressing the ongoing cyber threats posed by Russian military intelligence, highlighting the need for continued vigilance and international cooperation in cybersecurity efforts.
