Can I detect Indicators of Compromise for recent APT28 attacks on Mikrotik devices?

These are old attacks.

What we have observed happened early this morning across dozens of devices. Many of them had no service ports exposed to the internet (and in others, access was filtered via /ip services).

Observed behavior:

  • PPPoE clients showing 3–4 sessions per user.
    If you disconnect them, they reappear with the same uptime they previously had.
    Disabling the PPPoE server does not change anything.

  • CPU usage above 80%

  • Firewall rules in input chain allowing TCP connections to ports 1080, 7777, and 8888, without any prior login traces

  • 2 supout files created

  • All actions under System > Logging changed to "disk"

All of this activity was detected around 03:00 AM, while the CPU load and PPPoE issues started around 05:00 AM.

After a reboot, everything appears to return to normal.

So far, all affected devices are CCR Tilera running RouterOS 6.4x.