Firmware Intrusion & Espionage: Dual Waves by Islamist Hacktivists and APT28 Targeting Global Logistics Networks
Summary of the Attack: On July 20, 2025, security researchers uncovered a coordinated two-pronged cyber campaign. One wave was attributed to pro-Islamist hacktivist collectives—Cyber Jihad Movement (CJM), Muslim Cyber Hacktivity (MCH), Anonymous Muslim Unity (AMU), and the Allied Muslim Hacktivist Coalition (AMHC)—launching public, disruptive operations. Simultaneously, the sophisticated nation-state actor APT28 (Fancy Bear) carried out stealthy espionage targeting logistics companies across NATO allied states. Though seemingly separate, forensic clues suggest both waves exploited similar router and SaaS access vulnerabilities. Artifacts Discovered: Modified router firmware packages—bearing Islamic slogans and subtle malicious payloads within the bootloader region (CJM wave). SNMP logs showing exploitation of CVE-2017-6742 in Cisco devices and compromised Ubiquiti EdgeRouters (APT28 wave). Email mailbox permission alterations (e.g., Exchange and...