/
    Zpět na blog
    Security Sunday

    Russian GRU Abuses Vulnerable TP-Link Routers for Espionage


    Russian GRU Abuses Vulnerable TP-Link Routers for Espionage

    image

    Russia’s GRU kicked out of TP-Link routers around the world. The Hungarian government with the password ‘snoopy’. Anthropic and its Claude Mythos with Project Glasswing. And finally, a rootkit that steals WhatsApp accounts. Welcome to Security Sunday.

    The U.S. Department of Justice and the FBI announced a court-authorized technical operation aimed at neutralizing the American portion of a network of compromised SOHO routers controlled by Unit 26165 of Russia’s GRU military intelligence — also known as APT28, Fancy Bear, or Forest Blizzard.

    The Czech Republic joined the warning alongside Germany, Italy, Poland, Ukraine, the Baltic states, and other allies.

    The attack technique is uncomfortably simple — and that’s precisely where its power lies. According to Western authorities, the attackers exploited a known vulnerability in TP-Link devices, specifically CVE-2023–50224. Once inside the router, they changed DNS settings and pointed the resolvers to Russian-controlled infrastructure.

    Connected devices automatically picked up the new settings, and the attacker-controlled infrastructure then intercepted DNS queries for all domains, returning spoofed pages for selected services.

    The campaign likely ran since 2024, and the GRU compromised a wide range of routers worldwide. They then filtered out users from the military, government, and critical infrastructure sectors.

    According to court documents, the FBI developed a series of scripts that were pushed to compromised routers in the United States. These scripts were designed to collect evidence of GRU activity, reset the DNS configuration, and block the attackers from regaining access.

    Operation Masquerade effectively removed the GRU from American networks. It’s important to realize, however, that the FBI cannot fix routers in Brno, Prague, or Bratislava — and for end-of-life devices, not even the manufacturer can.

    Are you sure your systems are secure?

    Every week we bring real-world examples of attacks and vulnerabilities that can hit anyone. If you’re unsure whether your infrastructure is resilient, we’d be glad to help you find out. At SYSNETSHIELD we offer vulnerability scans, penetration tests, red teaming, and phishing simulations.

    Write to us at team@sysnetshield.com — the first consultation is free.

    When AI Rewrites the Rules of Cyber Defense | Project Glasswing and Claude Mythos

    Anthropic introduced Claude Mythos Preview — and immediately announced it would not be released publicly because it’s simply too good at finding security flaws.

    According to Anthropic, the model discovered, among other things, a 27-year-old bug in OpenBSD where just a handful of packets is enough to crash the server, a 16-year-old flaw in FFmpeg, an autonomous root exploit on Linux, and an RCE in the FreeBSD NFS server.

    Instead of a normal release, Anthropic launched Project Glasswing — a coalition with Microsoft, Apple, Google, AWS, Nvidia, Cisco, CrowdStrike, the Linux Foundation, and 40+ other organizations.

    The goal: patch critical holes before attackers find them.

    Alongside the major corporations, roughly forty additional organizations responsible for critical infrastructure also have access to the model.

    The results from initial testing are both fascinating and unsettling for any pentester. According to Anthropic’s report, Mythos Preview identified thousands of zero-day vulnerabilities in just a few weeks — many of them critical and difficult to detect. Some of the discovered flaws had gone unnoticed for years. The oldest was a 27-year-old bug in OpenBSD, a system famous for its emphasis on security.

    Anthropic does not plan to make Mythos Preview a public model. At the same time, the company intends to release the Mython family once new safety mechanisms are ready. Anthropic itself acknowledges that the same capabilities that help defenders can be abused by attackers.

    “snoopy” Protects the Hungarian Government

    The investigative team Bellingcat published an analysis revealing nearly 800 Hungarian government email addresses circulating online together with their passwords.

    The analysis showed that 12 out of 13 government ministries were affected. These weren’t rank-and-file clerks. Among the accounts were a senior military officer responsible for information security, a counter-terrorism coordinator at the Ministry of Foreign Affairs, and an employee whose job was to identify hybrid threats against the country.

    Perhaps most striking are the passwords themselves. Among the leaked credentials were the login details of a deputy state secretary who used the password “snoopy.” Other employees used their date of birth, or the word “Jelszo” — the Hungarian word for “password.”

    Other examples included “adolf,” “Batman2013,” “FrankLampard,” and the eternal “Password.” One employee at the Ministry of Defense simply used their last name; another from Foreign Affairs went with “embassy13hungary.”

    Bellingcat emphasizes that this is not a sophisticated attack. The findings are not evidence of a high-tech infiltration of Hungarian government systems. Instead, the analysis suggests the leaks are likely the result of poor digital hygiene. In many cases, employees used simple passwords together with their official email addresses for clearly non-work purposes.

    This is not the first time Hungary’s digital security has come under scrutiny. In 2022, investigative reporting revealed that Russian intelligence services had gained access to the IT systems of the Ministry of Foreign Affairs.

    No red team or APT group needs to invent sophisticated techniques when a state official responsible for hybrid threats protects their account with the password “snoopy.”

    Android Rootkit NoVoice Steals WhatsApp Accounts

    Researchers at McAfee uncovered a large-scale malware campaign called Operation NoVoice, hidden in more than 50 applications available directly on the official Google Play store. Together, these apps were downloaded by at least 2.3 million users. The malicious programs masqueraded as harmless tools — memory cleaners, simple games, or photo galleries.

    The apps worked exactly as advertised and didn’t request any suspicious permissions.

    The real danger lurked beneath the surface. After the app launched, an encrypted payload was extracted from a bundled PNG image, stored after the image’s end-of-file marker. The malware then attempted to gain root privileges by exploiting older Android vulnerabilities patched between 2016 and 2021.

    McAfee identified a total of 22 different exploits, including kernel attacks via IPv6 and vulnerabilities in Mali GPU drivers. After successful privilege escalation, NoVoice was able to disable SELinux and take full control of the device.

    On older phones running Android 7 or below, the infection cannot even be removed by a factory reset. The only solution is a complete firmware reflash — something the average user with a locked bootloader can hardly do.

    The only payload researchers managed to capture was a module called PtfLibc, focused on WhatsApp. When the messenger launched, the malware silently copied encrypted databases, Signal protocol keys, registration identifiers, the phone number, and metadata for Google Drive backups. With this data, attackers were able to clone the entire WhatsApp session onto their own device, read private conversations, impersonate the victim, and attack their contacts.

    McAfee notes that NoVoice shows strong similarities to the notorious Triada family — sharing the same persistence mechanism.

    After being notified, Google removed all affected apps from the Play Store and blocked the corresponding developer accounts. A spokesperson also confirmed that phones with the May 2021 security patch or later are protected against the exploited vulnerabilities.

    © 2026 Patrik Žák. Všechna práva vyhrazena.