Russia's military intelligence unit Sandworm has hacked over 300,000 consumer routers worldwide in a covert operation that transforms home Wi-Fi into listening posts and attack launchpads. The campaign, which targeted largely unpatched routers from four major manufacturers, exploits a known vulnerability in firmware chips that was disclosed in 2024 but remains unpatched on 58% of affected devices. Infected routers are being used to proxy cyberattacks against Ukrainian infrastructure, with one botnet cluster launching 12,000 DDoS attacks per hour. This scale of exploitation outperforms #7's limited-security test scenarios by orders of magnitude, as the compromised routers now span 80 countries. The average affected household faces no noticeable slowdown but remains at risk: the routers exfiltrate 500 MB of metadata daily without triggering ISP alerts. Victims are unlikely to ever know, as the malware self-destructs if a router is reset, erasing all forensic evidence in under three seconds. This campaign represents the largest covert router hijack since the 2018 VPNFilter attack.

Comments on "Thousands of consumer routers hacked by Russia's military"
Create a free account or sign in to join the discussion.
Sign in to join the conversation