Operation Masquerade disrupts APT28 campaign against 18,000 routers
Through Operation Masquerade, law enforcement agencies and private partners have carried out a coordinated disruption of a major campaign tied to the Russian intelligence group APT28. The actor targeted more than 18,000 small office and home office routers worldwide, using unauthorised access to redirect traffic and mount adversary-in-the-middle attacks. Both the FBI and Microsoft have published details of the operation.
What this means for your organisation
The router in a home office or a small branch site rarely has an owner. It sits where it sits, it does not get updated, and it usually falls outside both the IT inventory and the risk register. When traffic can be redirected the way described here, the real problem is not the technical detail but that staff working from home are effectively working through equipment nobody is accountable for. For organisations with hybrid working, this is a gap sitting outside your own firewall.
Berigo recommends
- Require home office traffic to travel through your own controlled channels, so a compromised home network yields no visibility.
- Identify small branch sites with router setups nobody in IT owns or maintains.
- Ask employees to update the firmware on their own network equipment, as a concrete task with a deadline rather than general advice.
- Replace network equipment that no longer receives security updates from the manufacturer.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch