APT28: DNS Hijacking and AitM Detections for SOHO Router Compromise
APT28 is conducting DNS hijacking campaigns against SOHO routers to perform adversary-in-the-middle attacks, intercepting credentials and communications at the network layer before they reach corporate infrastructure. This post covers 9 KQL detections across network telemetry, DNS, authentication, and device vulnerability data.
Read more →