The Czech Military Intelligence (VZ) worked with the American FBI to complete a successful international operation called Masquerade. The mission's goal was to stop the infrastructure of the hacker group APT28 (known as Fancy Bear), which is linked to Russian military intelligence (GRU).
How the Hackers Worked
The attackers used weaknesses in popular routers for small offices and homes, especially the TP-Link TL-WR841N model. After getting access to the devices, the hackers changed their settings and sent traffic to their own DNS servers. This allowed them to:
steal passwords and email data;
attack encrypted communication;
collect important strategic information about government and military targets in the Czech Republic and NATO countries.
Devices where users kept the factory passwords or did not update the software were especially weak.
Details of the Special Operation
During the operation, Czech experts actively intervened in the network's operation. Instead of just blocking the attacks, military intelligence remotely changed the settings of the hacked devices in the Czech Republic. This stopped the hackers from accessing them and made them safe for the future.
As emphasized by intelligence spokesperson Jan Pejsek, using home routers allowed hackers to not only hide who they were but also to use the worldwide infrastructure for cyberattacks for free.
Representatives from Czech intelligence services and the National Cyber and Information Security Agency (NÚKIB) remind everyone that the security of a country's critical infrastructure starts with each user. To avoid becoming an unintentional part of a hacker attack, citizens are strongly advised to:
Regularly update router software.
Set strong passwords that are different from the factory settings.
Check if the websites they visit are real.
The U.S. Embassy in Prague has already officially thanked their Czech colleagues for helping to stop Russian intelligence activities in cyberspace.


