hw_65cc4987483f03b4
Una red rusa de secuestro de DNS del GRU apuntó a sectores militares, gubernamentales y de infraestructura crítica en todo el mundo.
El Departamento de Justicia de EE. UU. y el FBI anunciaron una operación autorizada por un tribunal para desarticular una red de secuestro de DNS controlada por la Unidad Militar 26165 del GRU, también conocida como APT28 / Fancy Bear / Sofacy, una unidad de inteligencia militar rusa. Según el DOJ, los actores comprometieron miles de routers TP-Link de pequeñas oficinas y oficinas domésticas y los usaron para redirigir el tráfico de internet a través de resolutores DNS controlados por el GRU. El propósito de esa infraestructura era permitir ataques actor-in-the-middle contra objetivos seleccionados de interés de inteligencia para el gobierno ruso, incluidas personas y organizaciones de los sectores militar, gubernamental y de infraestructura crítica. El DOJ afirma que los compromisos iniciales de los routers fueron amplios e indiscriminados, tras lo cual el GRU filtró el tráfico para identificar comunicaciones que valía la pena interceptar. Para víctimas seleccionadas, la red servía registros DNS fraudulentos que imitaban servicios legítimos como Microsoft Outlook Web Access con el fin de recopilar contraseñas, tokens de autenticación, correos electrónicos y otra información sensible. Es menos adecuada para las categorías de espacio aéreo, marítima o sabotaje porque la operación fue digital y no cinética. Al mismo tiempo, el caso es útil para un rastreador de guerra híbrida centrado en Europa porque el DOJ dice explícitamente que el GRU usó los routers contra objetivos de todo el mundo, lo que significa que organizaciones europeas formaron plausiblemente parte del entorno de víctimas aunque el comunicado no enumere países europeos específicos.
Puntuaciones E/M/R/S
- EExistencia0/4 · Sin evaluar
- MIntención0/4 · Sin evaluar
- RVínculo con actor ruso0/4 · Sin evaluar
- SResponsabilidad del Estado ruso0/4 · Sin evaluar
Hechos
Sin hechos
Fuentes
-
- Rol
- discovery_lead
- Fecha
- 2026-04-06T22:38:36Z
The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a DNS-hijacking network controlled by GRU Military Unit 26165, also known as APT28 / Fancy Bear / Sofacy, a Russian military intelligence unit. According to the DOJ, the actors compromised thousands of TP-Link small office and home office routers and used them to redirect internet traffic through GRU-controlled DNS resolvers. The purpose of that infrastructure was to enable actor-in-the-middle attacks against selected targets of intelligence interest to the Russian government, including people and organizations in the military, government, and critical infrastructure sectors. The DOJ states that the initial router compromises were broad and indiscriminate, after which the GRU filtered traffic to identify communications worth intercepting. For selected victims, the network served fraudulent DNS records that mimicked legitimate services such as Microsoft Outlook Web Access in order to harvest passwords, authentication tokens, emails, and other sensitive information. It is less suitable for the airspace, maritime, or sabotage categories because the operation was digital rather than kinetic. At the same time, the case is useful for a Europe-focused hybrid-war tracker because the DOJ explicitly says the GRU used the routers against worldwide targets, which means European organizations were plausibly part of the victim environment even if the release does not list specific European countries.