Alpha Cyber

Graphing Fancy Bear’s Attack on Ubiquiti Routers: Infrastructure Mapping as a Service

In the ever-evolving cyber threat landscape, advanced persistent threats (APTs) continue to grow in complexity and scale.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Fancy bear Russia

Fancy Bear AKA APT-28 Ubiquiti Routers Campaign Graph

In the ever-evolving cyber threat landscape, advanced persistent threats (APTs) continue to grow in complexity and scale. One such adversary, Fancy Bear (APT28), has recently expanded its operational footprint, leveraging compromised Ubiquiti routers to deploy sophisticated command-and-control (C2) infrastructure.

At Alpha Cyber, we offer a dedicated service that maps, visualizes, and contextualizes adversarial infrastructure across enterprise and cloud environments. In this case, we’ve built a graph-based representation of Fancy Bear’s infrastructure targeting Ubiquiti routers, revealing relationships between infected assets, malicious binaries, and lateral movement techniques.

Why Target Ubiquiti Routers?

Ubiquiti routers, widely used in both corporate and home networks, are a lucrative target for state-sponsored actors due to:

  • Infrequent firmware updates
  • Default credentials or weak configurations
  • Their ability to operate as stealthy relay points for C2 traffic

Once compromised, these routers serve as resilient pivots for long-term campaigns, obfuscating the attacker’s origin and enabling the redirection of malicious traffic.

Infrastructure Mapping: A Strategic View of the Threat

Fancy Bear Attack on Ubiquiti Routers Graph

Through automated infrastructure graphing, we correlate:

  • Compromised router IPs and hostnames
  • Associated malware hashes
  • Communication with malicious domains or IPs
  • Lateral movement across internal assets

Our mapping allows real-time visualization of Fancy Bear’s operational infrastructure. This service helps clients quickly:

  • Identify exposure paths
  • Prioritize remediation
  • Understand the scope of infection across hybrid networks
  • Indicators of Compromise (IOCs)

We’ve compiled a list of verified IOCs linked to this campaign. These should be blocked or closely monitored in your network and endpoint security solutions.

Hash TypeValue
MD5050e2d68903681dbde4acd5ce83aea01
47f4b4d8f95a7e842691120c66309d5b
ee04beb64d15f6873309b9637d38a39e
4b4e7ccb1f015a107ac052ba25dfe94e
SHA-1bf01902ffa7ecb530b410ea4e1b769a9c16f74a3
1922698073911b18f60edd84ff8d13461fbd4c5a
2d47848e5e7e31125aa60cd2d89da2b8617fab04
25fca7e8a65bcdabdad9e4dc41dbb4649dedebdc
SHA-2560429bdc6a302b4288aea1b1e2f2a7545731c50d647672fa65b012b2a2caa386e
18f891a3737bb53cd1ab451e2140654a376a43b2d75f6695f3133d47a41952b6
40a7fd89b9e51b0a515ac2355036d203357be90a2200b9c506b95c12db54c7aa
104e3ea9a190ba039488f5200824fe883b98f6fe01d05a1b55e15ed2199c807a

Note: These IOCs have been validated through malware sandboxing and passive DNS telemetry. They are tied to malware samples used in the initial compromise and subsequent lateral movement stages.
Our Services Help You Stay Ahead


Our Threat Infrastructure Mapping Service is ideal for:

  •   1.Enterprise SOCs seeking visibility into active threats
       2.MSPs managing fleet security across multiple locations
       3.Incident response teams handling Fancy Bear-linked alerts
       4.Government and defense contractors with high risk exposure

We empower clients with:

   1.Tailored infrastructure graphs
   2.Continuous IOC enrichment
   3.Automated alerts on adversary infrastructure evolution
   4.Assistance in proactive blocking via firewall, proxy, and EDR integrations

Get Proactive Not Just Reactive

Fancy Bear continues to weaponize edge devices like Ubiquiti routers, turning them into reliable strongholds. By mapping their attack infrastructure, organizations can strike at the root of the campaign, not just its symptoms.

Protect your perimeter. Visualize the threat. Strengthen your defenses.
Contact Alpha Cyber today to learn how our Infrastructure Mapping Services can help you uncover and neutralize adversary activity before it takes root.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]