German Intelligence Warns of Russian APT28 Cyber Espionage, Targeting Military to Vital Infrastructure
JAKARTA - The Federal Office for the Protection of the Constitution (BfV) domestic intelligence agency warned of increased cyber espionage activities by a hacker group allegedly linked to Russia, APT28, targeting the military, government, and critical infrastructure sectors.
In its official statement, the BfV revealed that the group, also known as "Fancy Bear", had exploited a vulnerability in the TP-Link brand internet router to infiltrate the victim's network.
The attack was carried out globally with thousands of affected devices, including around 30 vulnerable routers in Germany. In some cases, system compromises have been confirmed, forcing operators to replace infected devices to prevent further damage.
The BfV said this warning was issued jointly with a number of strategic partners, including Germany's foreign intelligence agency, the Federal Intelligence Service (BND), and the Federal Bureau of Investigation from the United States.
APT28 itself by Western governments is linked to Russia's military intelligence agency, the GRU, and has a long track record of high-profile cyber operations.
The group has previously been involved in attacks on the German parliament, the Social Democratic Party of Germany (SPD), and air traffic control authorities - indicating a focus on sensitive strategic targets.
Technically, router exploitation is an increasingly popular tactic in modern cyber operations. By mastering network devices at the initial layer, hackers can access data traffic, infiltrate deeper into internal systems, and even launch advanced attacks undetected.
This warning from Germany comes amid rising global geopolitical tensions, where war is no longer only on land, sea, or air, but also in digital networks. Civilian infrastructure is now a soft target, while everyday devices such as home routers are turning into an entry point for state intelligence operations.
Security analysts assess that attacks like this are not just data theft, but part of a long-term strategy to build latent access - which can be activated at any time in an open conflict situation.
Follow VOI Whatsapp Channel