Lyce · Hybrid Watch

hw_65cc4987483f03b4

Una rete russa del GRU per il dirottamento DNS ha preso di mira in tutto il mondo i settori militare, governativo e delle infrastrutture critiche.

Il Dipartimento di Giustizia degli Stati Uniti e l’FBI hanno annunciato un’operazione autorizzata da un tribunale per interrompere una rete di dirottamento DNS controllata dall’Unità militare 26165 del GRU, nota anche come APT28 / Fancy Bear / Sofacy, un’unità dell’intelligence militare russa. Secondo il DOJ, gli attori hanno compromesso migliaia di router TP-Link per piccoli uffici e uffici domestici e li hanno usati per reindirizzare il traffico internet attraverso resolver DNS controllati dal GRU. Lo scopo di tale infrastruttura era consentire attacchi actor-in-the-middle contro obiettivi selezionati di interesse d’intelligence per il governo russo, comprese persone e organizzazioni nei settori militare, governativo e delle infrastrutture critiche. Il DOJ afferma che le compromissioni iniziali dei router erano ampie e indiscriminate, dopodiché il GRU ha filtrato il traffico per identificare comunicazioni meritevoli di intercettazione. Per vittime selezionate, la rete forniva record DNS fraudolenti che imitavano servizi legittimi come Microsoft Outlook Web Access al fine di raccogliere password, token di autenticazione, e-mail e altre informazioni sensibili. È meno adatta alle categorie spazio aereo, marittima o sabotaggio perché l’operazione era digitale piuttosto che cinetica. Allo stesso tempo, il caso è utile per un tracker della guerra ibrida focalizzato sull’Europa perché il DOJ afferma esplicitamente che il GRU ha usato i router contro obiettivi in tutto il mondo, il che significa che organizzazioni europee facevano plausibilmente parte dell’ambiente delle vittime anche se il comunicato non elenca paesi europei specifici.

Evento
2026-04-07
Pubblicazione
2026-04-06T22:38:36Z
Prima osservazione
2026-09-24T06:09:10.079Z
Stato revisione
Non valutato
Paesi
UA, US
Aggiornato
2026-09-30T10:02:34.709Z

Punteggi E/M/R/S

  • EEsistenza0/4 · Non valutato
  • MIntento0/4 · Non valutato
  • RLegame con attore russo0/4 · Non valutato
  • SResponsabilità dello Stato russo0/4 · Non valutato

Fatti

Nessun fatto

Fonti

  1. Ruolo
    discovery_lead
    Data
    2026-04-06T22:38:36Z

    The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a DNS-hijacking network controlled by GRU Military Unit 26165, also known as APT28 / Fancy Bear / Sofacy, a Russian military intelligence unit. According to the DOJ, the actors compromised thousands of TP-Link small office and home office routers and used them to redirect internet traffic through GRU-controlled DNS resolvers. The purpose of that infrastructure was to enable actor-in-the-middle attacks against selected targets of intelligence interest to the Russian government, including people and organizations in the military, government, and critical infrastructure sectors. The DOJ states that the initial router compromises were broad and indiscriminate, after which the GRU filtered traffic to identify communications worth intercepting. For selected victims, the network served fraudulent DNS records that mimicked legitimate services such as Microsoft Outlook Web Access in order to harvest passwords, authentication tokens, emails, and other sensitive information. It is less suitable for the airspace, maritime, or sabotage categories because the operation was digital rather than kinetic. At the same time, the case is useful for a Europe-focused hybrid-war tracker because the DOJ explicitly says the GRU used the routers against worldwide targets, which means European organizations were plausibly part of the victim environment even if the release does not list specific European countries.