⏱ 2 min read
Russian hackers hijacked thousands of Philly routers to siphon sensitive data from military, government, and critical infrastructure targets worldwide.
Since at least 2024, GRU actors exploited known vulnerabilities in TP-Link routers to steal credentials and manipulate settings, redirecting DNS requests to GRU-controlled servers.
Compromised routers in Philly were used to facilitate malicious DNS resolvers, intercepting and harvesting unencrypted passwords, authentication tokens, emails, and other sensitive information.
U.S. authorities, aided by the FBI, conducted a court-authorized technical operation to neutralize the U.S. portion of the GRU-controlled network, protecting critical data from further exploitation.
📋 Key Facts
- Crime: Cybercrime
- Defendant: Pennsylvania
- Location: PA
- Source: DOJ Press Release

