Germany Warns of Russian APT28 Cyber Espionage Targeting TP-Link Routers

Germany’s domestic intelligence agency, Federal Office for the Protection of the Constitution (BfV), has issued a warning about cyber espionage campaigns carried out by the Russian-linked hacker group APT28, also known as “Fancy Bear.”

According to the advisory, the group exploited vulnerabilities in TP-Link internet routers to gain access to networks and conduct surveillance on military, government, and critical infrastructure targets. The warning was issued in coordination with Germany’s foreign intelligence agency, Federal Intelligence Service (BND), and the Federal Bureau of Investigation.

Western authorities attribute APT28 to Russia’s military intelligence agency, the GRU. The group reportedly compromised thousands of routers worldwide, including approximately 30 devices in Germany, with confirmed breaches in some cases leading to the replacement of affected hardware.

The BfV noted that APT28 has a history of targeting German institutions, including previous attacks on the national parliament, the Social Democratic Party, and air traffic control systems.

The latest warning highlights ongoing cybersecurity risks associated with unpatched or vulnerable network devices and underscores the need for organizations to strengthen defenses against state-sponsored cyber threats.

Posted in ,