hw_65cc4987483f03b4
Rusijos GRU DNS užgrobimo tinklas visame pasaulyje taikėsi į karinius, vyriausybinius ir kritinės infrastruktūros sektorius.
JAV teisingumo departamentas ir FBI paskelbė apie teismo sankcionuotą operaciją, skirtą sutrikdyti DNS užgrobimo tinklą, kurį kontroliavo GRU karinis padalinys 26165, dar žinomas kaip APT28 / Fancy Bear / Sofacy, Rusijos karinės žvalgybos padalinys. Pasak DOJ, veikėjai kompromitavo tūkstančius TP-Link mažų biurų ir namų biurų maršrutizatorių ir naudojo juos interneto srautui nukreipti per GRU kontroliuojamus DNS resolverius. Šios infrastruktūros tikslas buvo sudaryti sąlygas actor-in-the-middle atakoms prieš pasirinktus Rusijos vyriausybei žvalgybiškai svarbius taikinius, įskaitant žmones ir organizacijas kariniame, vyriausybiniame ir kritinės infrastruktūros sektoriuose. DOJ teigia, kad pradiniai maršrutizatorių kompromitavimai buvo platūs ir nediskriminaciniai, po to GRU filtravo srautą, kad nustatytų ryšius, vertus perėmimo. Pasirinktoms aukoms tinklas teikė apgaulingus DNS įrašus, kurie imitavo teisėtas paslaugas, tokias kaip Microsoft Outlook Web Access, siekiant rinkti slaptažodžius, autentifikavimo žetonus, el. laiškus ir kitą neskelbtiną informaciją. Jis mažiau tinka oro erdvės, jūrų ar sabotažo kategorijoms, nes operacija buvo skaitmeninė, o ne kinetinė. Tuo pat metu atvejis naudingas į Europą orientuotam hibridinio karo sekikliui, nes DOJ aiškiai sako, kad GRU naudojo maršrutizatorius prieš taikinius visame pasaulyje, o tai reiškia, kad Europos organizacijos tikėtinai buvo aukų aplinkos dalis, net jei pranešime nenurodomos konkrečios Europos šalys.
E/M/R/S balai
- EEgzistavimas0/4 · Neįvertinta
- MKetinimas0/4 · Neįvertinta
- RRyšys su Rusijos veikėju0/4 · Neįvertinta
- SRusijos valstybės atsakomybė0/4 · Neįvertinta
Faktai
Faktų nėra
Šaltiniai
-
- Vaidmuo
- discovery_lead
- Data
- 2026-04-06T22:38:36Z
The U.S. Department of Justice and the FBI announced a court-authorized operation to disrupt a DNS-hijacking network controlled by GRU Military Unit 26165, also known as APT28 / Fancy Bear / Sofacy, a Russian military intelligence unit. According to the DOJ, the actors compromised thousands of TP-Link small office and home office routers and used them to redirect internet traffic through GRU-controlled DNS resolvers. The purpose of that infrastructure was to enable actor-in-the-middle attacks against selected targets of intelligence interest to the Russian government, including people and organizations in the military, government, and critical infrastructure sectors. The DOJ states that the initial router compromises were broad and indiscriminate, after which the GRU filtered traffic to identify communications worth intercepting. For selected victims, the network served fraudulent DNS records that mimicked legitimate services such as Microsoft Outlook Web Access in order to harvest passwords, authentication tokens, emails, and other sensitive information. It is less suitable for the airspace, maritime, or sabotage categories because the operation was digital rather than kinetic. At the same time, the case is useful for a Europe-focused hybrid-war tracker because the DOJ explicitly says the GRU used the routers against worldwide targets, which means European organizations were plausibly part of the victim environment even if the release does not list specific European countries.