Morning Overview

The FBI dismantled a Russian military botnet built from about 5,000 home and office routers

A network of ordinary internet routers, the kind sitting quietly in homes and small offices, was turned into a tool of Russian military intelligence before United States authorities moved to shut it down. The FBI announced that it had dismantled the operation, which had corralled roughly 5,000 compromised devices into a botnet used to mask the activity of state-backed hackers.

The case is a stark illustration of how everyday hardware can be conscripted into international espionage. The routers involved were not exotic equipment but commonplace consumer and business models, many of them older or poorly secured, that their owners had almost certainly forgotten about. Their obscurity was precisely what made them useful to attackers seeking to hide.

How GRU Unit 26165 built the network

According to the bureau’s announcement, the botnet was operated by GRU Unit 26165, a Russian military intelligence group also tracked by cybersecurity researchers under the name APT28. The FBI’s public advisory on the takedown described how the operators assembled the network from about 5,000 infected routers, using them to route malicious traffic and obscure the true source of their operations.

The advisory tied the activity to a broad campaign that reached across the country and beyond, touching more than 200 organizations and spanning at least 23 states. By funneling their traffic through a wide array of hijacked devices, the operators could make their intrusions appear to originate from unremarkable residential and commercial internet connections rather than from infrastructure obviously linked to a foreign government.

Why compromised routers are so valuable to spies

Routers are an attractive target for a reason. They sit at the edge of every network, running constantly and often overlooked once installed, and they rarely receive the same attention as laptops or phones when it comes to updates and security. A router that has not been patched in years can carry known vulnerabilities that attackers exploit to gain a foothold.

Once a device is compromised, it becomes a relay. State-backed operators can bounce their traffic through it, so that intrusion attempts and data theft appear to come from an innocent household or a small business rather than from an intelligence agency. The FBI’s cyber division, which documents this class of threat in its guidance on cyber operations, has repeatedly warned that edge devices are a favored staging ground for exactly this reason. Spreading activity across thousands of such devices also makes the operation resilient, since losing any single router barely dents the whole.

What a court-authorized takedown involves

Dismantling a botnet is not as simple as arresting its operators, who in this case sit beyond the reach of American law enforcement. Instead, authorities typically pursue court authorization to neutralize the malicious infrastructure directly, working to sever the attackers’ control over the compromised devices and, where possible, to clean the malicious code from them. The aim is to break the network’s command structure so it can no longer be used.

Operations of this kind are delicate because they involve reaching into privately owned equipment to remove hostile software without disrupting the devices’ normal function. Coordinating such an effort at scale, across thousands of routers in many jurisdictions, requires careful legal groundwork and technical precision. The result, when successful, is that the attackers lose their hidden relay network in a single coordinated stroke.

What router owners can take away from the case

For the owners of the affected devices, the most unsettling detail is that they were unlikely to have noticed anything wrong. A compromised router can keep delivering internet service normally while quietly serving a hostile purpose in the background, giving its owner no obvious sign that it has been hijacked. That invisibility is what allows such networks to persist for long stretches.

The episode reinforces a set of basic protections that security experts have urged for years. Keeping router firmware up to date, replacing hardware that no longer receives security patches, changing default passwords, and disabling remote management features all make a device far harder to conscript. Older equipment that manufacturers no longer support is especially vulnerable, since the flaws attackers exploit may never be fixed.

A pattern of hijacked edge devices

This operation was not an isolated event but the latest in a recurring struggle over the world’s edge hardware. Security agencies and researchers have increasingly warned that routers, home internet gateways, and other always-on devices sitting at the boundary of a network have become a preferred foothold for sophisticated attackers, precisely because they are numerous, exposed to the open internet, and rarely monitored. A single vulnerable model, sold in the millions, can furnish an attacker with a vast pool of potential relays.

The economics favor the attacker. Assembling a botnet from devices that other people own and maintain costs almost nothing compared with building dedicated infrastructure, and it shifts the burden of detection onto unwitting owners. Each disruption of such a network buys time and forces adversaries to rebuild, but the underlying supply of poorly secured devices remains, which is why authorities treat these takedowns as an ongoing campaign rather than a one-time fix.

Beyond the individual devices, the takedown underscores a broader shift in how state-backed espionage operates. Rather than relying solely on their own infrastructure, intelligence services increasingly borrow the anonymity of ordinary internet users, turning consumer hardware into cover. Disrupting that model, one botnet at a time, has become a recurring feature of the effort to counter foreign cyber operations, and this case shows both the reach of such campaigns and the coordinated response they now provoke.

This article was researched and written with the assistance of AI and reviewed by an editor prior to publication.


More from Morning Overview