INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russian APT Groups Target Network Devices
| 2026-07-15 18:59 CRITICAL HIGHExecutive Summary AI-generated
The Russian Federal Security Service's (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. These sophisticated threat groups mainly target routers by scanning the internet for exposed Simple Network Management Protocol (SNMP) services with weak or default credentials. Their techniques overlap with other nation-state actors, making it essential for organizations to monitor SNMP activity, restrict management access through Access Control Lists (ACLs), block unnecessary ports such as TFTP, SMI and SNMP from external networks, and detect suspicious configuration changes to defend against multiple threats.
Technical Mitigations AI-generated
* Disabling Cisco Smart Install and replacing SNMPv1/v2 with SNMPv3 using strong encryption can help secure network devices against Russian APT groups.
* Enforcing unique passwords, securing storage, monitoring SNMP activity, restricting management access through ACLs, blocking unnecessary ports such as TFTP, SMI, and SNMP from external networks, and keeping firmware updated are recommended measures to strengthen router security.
* Using attack surface management tools can help identify exposed systems and weak configurations in critical infrastructure sectors.
* Replacing unsupported devices and monitoring for suspicious configuration changes is essential to prevent further attacks by Russian hackers.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt TyphoonDragonflyDragonflyAPT28APT28
Lumma StealerLumma Stealer
CVE-2008-4128CVE-2008-4128
CVE-2018-0171CVE-2018-0171
Target & Sectors
NORDICS
NORDICS
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
healthhealth
governmentgovernment
healthcarehealthcare
financefinance
mediamedia
energyenergy
defensedefense
Incident Timeline
November 2021
Russian hackers used a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software to target vulnerable routers worldwide.
Click on any entity below to view its context and source!
attribution
CVE-2018-0171
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
attribution
FBI
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
infrastructure
Ios
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
attribution
Smart Install
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
attribution
Cisco IOS
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
late 2025
Threat actors used FSB Center 16 to target Poland's energy grid in late 2025.
Click on any entity below to view its context and source!
general_metric
16 cyber actors
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
industry
Energy
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
target_region
Poland
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
target_region
United Kingdom
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
source_region
EUROPE
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
organisation
EU
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
organisation
UK Blame
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
organisation
European Union
EU, UK Blame Center 16 for Poland’s Energy Grid Cyber-Attack
At the same time as the publication of the joint advisory, the coordinated cyber-attacks which targeted Poland’s energy infrastructure in late 2025 have been officially attributed to FSB Center 16 by the UK and European Union (EU).
August 2025
The FBI warned that Russian hackers targeted vulnerable routers worldwide using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software.
Click on any entity below to view its context and source!
attribution
CVE-2018-0171
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
attribution
FBI
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
infrastructure
Ios
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
attribution
Smart Install
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
attribution
Cisco IOS
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
December 2025
Russian Hackers Disrupted FrostArmada's Campaign to Infect 18,000 Routers Worldwide.
Click on any entity below to view its context and source!
target_region
Russian Federation
On Monday, the European Union blamed Russia’s FSB Center 16 for a December 2025 attack on Poland’s energy grid.
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
industry
Energy
On Monday, the European Union blamed Russia’s FSB Center 16 for a December 2025 attack on Poland’s energy grid.
target_region
Poland
On Monday, the European Union blamed Russia’s FSB Center 16 for a December 2025 attack on Poland’s energy grid.
target_region
EUROPE
On Monday, the European Union blamed Russia’s FSB Center 16 for a December 2025 attack on Poland’s energy grid.
organisation
the European Union
On Monday, the European Union blamed Russia’s FSB Center 16 for a December 2025 attack on Poland’s energy grid.
attribution
FBI
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
attribution
FrostArmada
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
threat_actor
APT28
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
attribution
GRU
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
attribution
Fancy Bear
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
infrastructure
18,000 routers
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
general_metric
120 countries
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
July 13
Russian hackers used compromised routers to target the UK government and 500,000 citizens worldwide.
Click on any entity below to view its context and source!
industry
Government
In a
statement issued on July 13
, the UK government said: “This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.
target_region
United Kingdom
In a
statement issued on July 13
, the UK government said: “This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.
general_metric
500,000 citizens
In a
statement issued on July 13
, the UK government said: “This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.
2026/07/15
Russian hackers targeted vulnerable routers worldwide using spoofed requests to steal device configurations and move them to attacker-controlled servers via Trivial File Transfer Protocol (TFTP).
Click on any entity below to view its context and source!
organisation
APT Groups
US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
US and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide.
organisation
APT
US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
US and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide.
organisation
CVE-2018-0171
“While SNMP scanning is the primary method the actors use to discover and exploit poorly configured networking devices, they occasionally exploit common vulnerabilities and exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices.”
Russia-linked threat actors have also exploited known vulnerabilities, including
CVE-2018-0171
and
CVE-2008-4128
, to compromise network devices.
In 2025, Cisco warned that a
seven-year-old vulnerability (CVE-2018-0171)
in the Smart Install feature of unpatched, often end-of-life Cisco devices, was being exploited by Center 16/Static Tundra.
organisation
SMI
“While SNMP scanning is the primary method the actors use to discover and exploit poorly configured networking devices, they occasionally exploit common vulnerabilities and exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices.”
Russia-linked threat actors have also exploited known vulnerabilities, including
CVE-2018-0171
and
CVE-2008-4128
, to compromise network devices.
While SNMP scanning is the primary method the actors use to discover and exploit poorly configured networking devices, they occasionally exploit common vulnerabilities and exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices.
"Whilst the actor primarily uses SNMP scans to locate and compromise vulnerable routers, they have also exploited well-known vulnerabilities relating to Cisco devices, Cisco's Smart Install (SMI) feature and web-portal flaws to gain control of network devices.
organisation
the Russian FSB Center
Two of the Cisco vulnerabilities exploited by the Russian FSB Center 16 hackers are quite old, including
CVE-2008-4128
and
CVE-2018-0171
.
The Russian FSB Center 16 cyber actors primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation.
organisation
CVE-2018
Two of the Cisco vulnerabilities exploited by the Russian FSB Center 16 hackers are quite old, including
CVE-2008-4128
and
CVE-2018-0171
.
Customers were urged to apply the
patch for CVE-2018-0171
or to disable Smart Install if patching is not an option.
organisation
CSA
Even though this CSA focuses on Russian FSB Center 16 cyber activity, the mitigations below should detect and counter these and similar TTPs used by other actors.
organisation
Russian State Hackers Target
Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns.
organisation
TFTP
Table 1: Reconnaissance
Technique Title
ID
Use
Active Scanning: Scanning IP Blocks
T1595.001
Scan range of IP addresses
Active Scanning: Vulnerability Scanning
T1595.002
Scan victims for vulnerabilities that can be used during targeting
Table 2: Resource Development
Technique Title
ID
Use
Acquire Infrastructure: Virtual Private Servers
T1583.003
Leverage VPS as infrastructure
Compromise Infrastructure: Network Devices
T1584.008
Compromise intermediate routers
Obtain Capabilities: Exploits
T1588.005
Use publicly available code to exploit vulnerable devices
Table 3: Initial Access
Technique Title
ID
Use
Exploit Public-Facing Application
T1190
Exploit publicly known CVEs
Proxy
T1090
Use a connection proxy to direct network traffic
Table 4: Execution
Technique Title
ID
Use
System Services
T1569
Executing commands via SNMP
Table 5: Privilege Escalation
Technique Title
ID
Use
Exploitation for Privilege Escalation
T1068
Exploit publicly known CVEs for escalated privileges
Table 6: Stealth
Technique Title
ID
Use
Obfuscated Files or Information
T1027
Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses
Table 7: Credential Access
Technique Title
ID
Use
OS Credential Dumping
T1003
Collect router configuration with weak Cisco Type 7 passwords and Type 0
Table 8: Collection
Technique Title
ID
Use
Data from Configuration Repository: SNMP (MIB Dump)
T1602.001
Target MIB to collect network information via SNMP
Data from Configuration Repository: Network Device Configuration Dump
T1602.002
Acquire credentials by collecting network device configurations
Table 9: Command and Control
Technique Title
ID
Use
Proxy
T1090
Use VPS for C2
Application Layer Protocol
T1071
Open and expose a variety of different services, including TFTP and FTP
Table 10: Exfiltration
Technique Title
ID
Use
Exfiltration Over Alternative Protocol
T1048
Exfiltrating over a different protocol than that of the existing command and control channel.
They use spoofed requests to steal device configurations and move them to attacker-controlled servers through TFTP or FTP.
organisation
Initial Access
Technique Title
ID
Table 1: Reconnaissance
Technique Title
ID
Use
Active Scanning: Scanning IP Blocks
T1595.001
Scan range of IP addresses
Active Scanning: Vulnerability Scanning
T1595.002
Scan victims for vulnerabilities that can be used during targeting
Table 2: Resource Development
Technique Title
ID
Use
Acquire Infrastructure: Virtual Private Servers
T1583.003
Leverage VPS as infrastructure
Compromise Infrastructure: Network Devices
T1584.008
Compromise intermediate routers
Obtain Capabilities: Exploits
T1588.005
Use publicly available code to exploit vulnerable devices
Table 3: Initial Access
Technique Title
ID
Use
Exploit Public-Facing Application
T1190
Exploit publicly known CVEs
Proxy
T1090
Use a connection proxy to direct network traffic
Table 4: Execution
Technique Title
ID
Use
System Services
T1569
Executing commands via SNMP
Table 5: Privilege Escalation
Technique Title
ID
Use
Exploitation for Privilege Escalation
T1068
Exploit publicly known CVEs for escalated privileges
Table 6: Stealth
Technique Title
ID
Use
Obfuscated Files or Information
T1027
Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses
Table 7: Credential Access
Technique Title
ID
Use
OS Credential Dumping
T1003
Collect router configuration with weak Cisco Type 7 passwords and Type 0
Table 8: Collection
Technique Title
ID
Use
Data from Configuration Repository: SNMP (MIB Dump)
T1602.001
Target MIB to collect network information via SNMP
Data from Configuration Repository: Network Device Configuration Dump
T1602.002
Acquire credentials by collecting network device configurations
Table 9: Command and Control
Technique Title
ID
Use
Proxy
T1090
Use VPS for C2
Application Layer Protocol
T1071
Open and expose a variety of different services, including TFTP and FTP
Table 10: Exfiltration
Technique Title
ID
Use
Exfiltration Over Alternative Protocol
T1048
Exfiltrating over a different protocol than that of the existing command and control channel.
organisation
Collect
Table 1: Reconnaissance
Technique Title
ID
Use
Active Scanning: Scanning IP Blocks
T1595.001
Scan range of IP addresses
Active Scanning: Vulnerability Scanning
T1595.002
Scan victims for vulnerabilities that can be used during targeting
Table 2: Resource Development
Technique Title
ID
Use
Acquire Infrastructure: Virtual Private Servers
T1583.003
Leverage VPS as infrastructure
Compromise Infrastructure: Network Devices
T1584.008
Compromise intermediate routers
Obtain Capabilities: Exploits
T1588.005
Use publicly available code to exploit vulnerable devices
Table 3: Initial Access
Technique Title
ID
Use
Exploit Public-Facing Application
T1190
Exploit publicly known CVEs
Proxy
T1090
Use a connection proxy to direct network traffic
Table 4: Execution
Technique Title
ID
Use
System Services
T1569
Executing commands via SNMP
Table 5: Privilege Escalation
Technique Title
ID
Use
Exploitation for Privilege Escalation
T1068
Exploit publicly known CVEs for escalated privileges
Table 6: Stealth
Technique Title
ID
Use
Obfuscated Files or Information
T1027
Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses
Table 7: Credential Access
Technique Title
ID
Use
OS Credential Dumping
T1003
Collect router configuration with weak Cisco Type 7 passwords and Type 0
Table 8: Collection
Technique Title
ID
Use
Data from Configuration Repository: SNMP (MIB Dump)
T1602.001
Target MIB to collect network information via SNMP
Data from Configuration Repository: Network Device Configuration Dump
T1602.002
Acquire credentials by collecting network device configurations
Table 9: Command and Control
Technique Title
ID
Use
Proxy
T1090
Use VPS for C2
Application Layer Protocol
T1071
Open and expose a variety of different services, including TFTP and FTP
Table 10: Exfiltration
Technique Title
ID
Use
Exfiltration Over Alternative Protocol
T1048
Exfiltrating over a different protocol than that of the existing command and control channel.
organisation
SNMP
Table 1: Reconnaissance
Technique Title
ID
Use
Active Scanning: Scanning IP Blocks
T1595.001
Scan range of IP addresses
Active Scanning: Vulnerability Scanning
T1595.002
Scan victims for vulnerabilities that can be used during targeting
Table 2: Resource Development
Technique Title
ID
Use
Acquire Infrastructure: Virtual Private Servers
T1583.003
Leverage VPS as infrastructure
Compromise Infrastructure: Network Devices
T1584.008
Compromise intermediate routers
Obtain Capabilities: Exploits
T1588.005
Use publicly available code to exploit vulnerable devices
Table 3: Initial Access
Technique Title
ID
Use
Exploit Public-Facing Application
T1190
Exploit publicly known CVEs
Proxy
T1090
Use a connection proxy to direct network traffic
Table 4: Execution
Technique Title
ID
Use
System Services
T1569
Executing commands via SNMP
Table 5: Privilege Escalation
Technique Title
ID
Use
Exploitation for Privilege Escalation
T1068
Exploit publicly known CVEs for escalated privileges
Table 6: Stealth
Technique Title
ID
Use
Obfuscated Files or Information
T1027
Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses
Table 7: Credential Access
Technique Title
ID
Use
OS Credential Dumping
T1003
Collect router configuration with weak Cisco Type 7 passwords and Type 0
Table 8: Collection
Technique Title
ID
Use
Data from Configuration Repository: SNMP (MIB Dump)
T1602.001
Target MIB to collect network information via SNMP
Data from Configuration Repository: Network Device Configuration Dump
T1602.002
Acquire credentials by collecting network device configurations
Table 9: Command and Control
Technique Title
ID
Use
Proxy
T1090
Use VPS for C2
Application Layer Protocol
T1071
Open and expose a variety of different services, including TFTP and FTP
Table 10: Exfiltration
Technique Title
ID
Use
Exfiltration Over Alternative Protocol
T1048
Exfiltrating over a different protocol than that of the existing command and control channel.
organisation
Command
Table 1: Reconnaissance
Technique Title
ID
Use
Active Scanning: Scanning IP Blocks
T1595.001
Scan range of IP addresses
Active Scanning: Vulnerability Scanning
T1595.002
Scan victims for vulnerabilities that can be used during targeting
Table 2: Resource Development
Technique Title
ID
Use
Acquire Infrastructure: Virtual Private Servers
T1583.003
Leverage VPS as infrastructure
Compromise Infrastructure: Network Devices
T1584.008
Compromise intermediate routers
Obtain Capabilities: Exploits
T1588.005
Use publicly available code to exploit vulnerable devices
Table 3: Initial Access
Technique Title
ID
Use
Exploit Public-Facing Application
T1190
Exploit publicly known CVEs
Proxy
T1090
Use a connection proxy to direct network traffic
Table 4: Execution
Technique Title
ID
Use
System Services
T1569
Executing commands via SNMP
Table 5: Privilege Escalation
Technique Title
ID
Use
Exploitation for Privilege Escalation
T1068
Exploit publicly known CVEs for escalated privileges
Table 6: Stealth
Technique Title
ID
Use
Obfuscated Files or Information
T1027
Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses
Table 7: Credential Access
Technique Title
ID
Use
OS Credential Dumping
T1003
Collect router configuration with weak Cisco Type 7 passwords and Type 0
Table 8: Collection
Technique Title
ID
Use
Data from Configuration Repository: SNMP (MIB Dump)
T1602.001
Target MIB to collect network information via SNMP
Data from Configuration Repository: Network Device Configuration Dump
T1602.002
Acquire credentials by collecting network device configurations
Table 9: Command and Control
Technique Title
ID
Use
Proxy
T1090
Use VPS for C2
Application Layer Protocol
T1071
Open and expose a variety of different services, including TFTP and FTP
Table 10: Exfiltration
Technique Title
ID
Use
Exfiltration Over Alternative Protocol
T1048
Exfiltrating over a different protocol than that of the existing command and control channel.
organisation
C2
Table 1: Reconnaissance
Technique Title
ID
Use
Active Scanning: Scanning IP Blocks
T1595.001
Scan range of IP addresses
Active Scanning: Vulnerability Scanning
T1595.002
Scan victims for vulnerabilities that can be used during targeting
Table 2: Resource Development
Technique Title
ID
Use
Acquire Infrastructure: Virtual Private Servers
T1583.003
Leverage VPS as infrastructure
Compromise Infrastructure: Network Devices
T1584.008
Compromise intermediate routers
Obtain Capabilities: Exploits
T1588.005
Use publicly available code to exploit vulnerable devices
Table 3: Initial Access
Technique Title
ID
Use
Exploit Public-Facing Application
T1190
Exploit publicly known CVEs
Proxy
T1090
Use a connection proxy to direct network traffic
Table 4: Execution
Technique Title
ID
Use
System Services
T1569
Executing commands via SNMP
Table 5: Privilege Escalation
Technique Title
ID
Use
Exploitation for Privilege Escalation
T1068
Exploit publicly known CVEs for escalated privileges
Table 6: Stealth
Technique Title
ID
Use
Obfuscated Files or Information
T1027
Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses
Table 7: Credential Access
Technique Title
ID
Use
OS Credential Dumping
T1003
Collect router configuration with weak Cisco Type 7 passwords and Type 0
Table 8: Collection
Technique Title
ID
Use
Data from Configuration Repository: SNMP (MIB Dump)
T1602.001
Target MIB to collect network information via SNMP
Data from Configuration Repository: Network Device Configuration Dump
T1602.002
Acquire credentials by collecting network device configurations
Table 9: Command and Control
Technique Title
ID
Use
Proxy
T1090
Use VPS for C2
Application Layer Protocol
T1071
Open and expose a variety of different services, including TFTP and FTP
Table 10: Exfiltration
Technique Title
ID
Use
Exfiltration Over Alternative Protocol
T1048
Exfiltrating over a different protocol than that of the existing command and control channel.
organisation
Cybersecurity Services
United States Department of Defense Cyber Crime Center (DC3)
Defense Industrial Base Inquiries and Cybersecurity Services:
[email protected]
Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at
.
organisation
Defense Federal Acquisition Regulation Supplement
United States Department of Defense Cyber Crime Center (DC3)
Defense Industrial Base Inquiries and Cybersecurity Services:
[email protected]
Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at
.
organisation
DFARS
United States Department of Defense Cyber Crime Center (DC3)
Defense Industrial Base Inquiries and Cybersecurity Services:
[email protected]
Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at
.
organisation
Russian Federal Security Service
“Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks.”
The joint advisory detailed how Russian Federal Security Service (FSB) Center 16 cyber actors have been observed hunting for vulnerable routers by scanning the internet for devices that still use default or weak Simple Network Management Protocol (SNMP) passwords and community strings.
organisation
the Russian Federal Security Service Center
Officials once again urged defenders to take more preventative measures to thwart attacks from the Russian Federal Security Service Center 16, which has been actively targeting critical infrastructure for more than a decade.
organisation
Simple Network Management Protocol (
The joint advisory detailed how Russian Federal Security Service (FSB) Center 16 cyber actors have been observed hunting for vulnerable routers by scanning the internet for devices that still use default or weak Simple Network Management Protocol (SNMP) passwords and community strings.
"Centre 16 [..] has been seen hunting for vulnerable routers by scanning the internet for devices that still use default or weak Simple Network Management Protocol (SNMP) passwords and community strings," the UK National Cyber Security Centre
warned
on Monday.
The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication” continues the joint advisory.
The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication
organisation
Smart Install
In 2025, Cisco warned that a
seven-year-old vulnerability (CVE-2018-0171)
in the Smart Install feature of unpatched, often end-of-life Cisco devices, was being exploited by Center 16/Static Tundra.
"Whilst the actor primarily uses SNMP scans to locate and compromise vulnerable routers, they have also exploited well-known vulnerabilities relating to Cisco devices, Cisco's Smart Install (SMI) feature and web-portal flaws to gain control of network devices.
organisation
Center
In 2025, Cisco warned that a
seven-year-old vulnerability (CVE-2018-0171)
in the Smart Install feature of unpatched, often end-of-life Cisco devices, was being exploited by Center 16/Static Tundra.
organisation
National Cyber Security Centre
"Centre 16 [..] has been seen hunting for vulnerable routers by scanning the internet for devices that still use default or weak Simple Network Management Protocol (SNMP) passwords and community strings," the UK National Cyber Security Centre
warned
on Monday.
threat_actor
Dragonfly
Crouching Yeti
,
Dragonfly
, and
Static Tundra
, have targeted organizations in communications, defense, energy, finance, government, and healthcare sectors.
Center 16 is also known as Berserk Bear, Energetic Bear, Crouching Yeti,
Dragonfly
, Ghost Blizzard and Static Tundra.
Sectors most at risk from this global targeting, including communications, defence, energy, financial services, government and healthcare, are being urged to take action.
The hackers are also tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra.
Although not all encompassing, the following list contains the most notable threat group names commonly used within the cybersecurity community related to this activity:
Berserk Bear
Energetic Bear
Crouching Yeti
Dragonfly
Ghost Blizzard
Static Tundra
Note: Cybersecurity companies have different methods of tracking and attributing cyber actors, and this list may not provide a 1:1 correlation to the authoring agencies’ understanding for all activity related to these groupings.
This hacking group (tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra) scans internet-connected IP address ranges for routers accepting default or common SNMP authentication strings, then issues commands using spoofed IP addresses to copy device configuration files and exfiltrate them via the Trivial File Transfer Protocol to actor-controlled servers.
organisation
Berserk Bear
The hackers are also tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra.
This hacking group (tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra) scans internet-connected IP address ranges for routers accepting default or common SNMP authentication strings, then issues commands using spoofed IP addresses to copy device configuration files and exfiltrate them via the Trivial File Transfer Protocol to actor-controlled servers.
Groups linked to FSB Center 16, including
Berserk Bear
,
Energetic Bear
,
Ghost Blizzard
,
organisation
IP
This hacking group (tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra) scans internet-connected IP address ranges for routers accepting default or common SNMP authentication strings, then issues commands using spoofed IP addresses to copy device configuration files and exfiltrate them via the Trivial File Transfer Protocol to actor-controlled servers.
These scans, run via proxies, consist of SNMP Set-Requests from a spoofed IP address
organisation
the Trivial File Transfer Protocol
This hacking group (tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra) scans internet-connected IP address ranges for routers accepting default or common SNMP authentication strings, then issues commands using spoofed IP addresses to copy device configuration files and exfiltrate them via the Trivial File Transfer Protocol to actor-controlled servers.
organisation
Groups
Groups linked to FSB Center 16, including
Berserk Bear
,
Energetic Bear
,
Ghost Blizzard
,
organisation
FTP
They use spoofed requests to steal device configurations and move them to attacker-controlled servers through TFTP or FTP.
Transfer the file, typically using Trivial File Transfer Protocol (TFTP), to an actor-controlled leased virtual private server (VPS) or compromised FTP server [
T1583.003
,
T1090
,
organisation
Trivial File Transfer Protocol
Transfer the file, typically using Trivial File Transfer Protocol (TFTP), to an actor-controlled leased virtual private server (VPS) or compromised FTP server [
T1583.003
,
T1090
,
If an attacker obtains a valid community string and gains successful SNMP access, they can use Object Identifiers (OIDs) to command the router to copy its configurations and send it via Trivial File Transfer Protocol (TFTP).
organisation
VPS
Transfer the file, typically using Trivial File Transfer Protocol (TFTP), to an actor-controlled leased virtual private server (VPS) or compromised FTP server [
T1583.003
,
T1090
,
threat_actor
Salt Typhoon
Their techniques overlap with other threat groups, such as
Salt Typhoon
.
T1068
]:
Many of these TTPs overlap with activity by other malicious cyber actors, such as
Salt Typhoon
.
organisation
ACLs
Organizations should monitor SNMP activity, restrict management access through ACLs, block unnecessary ports such as TFTP, SMI and SNMP from external networks, and detect suspicious configuration changes.
organisation
New Zealand National Cyber Security Centre
New Zealand National Cyber Security Centre (NCSC-NZ)
United Kingdom National Cyber Security Centre (NCSC-UK)
organisation
United Kingdom National Cyber Security Centre
New Zealand National Cyber Security Centre (NCSC-NZ)
United Kingdom National Cyber Security Centre (NCSC-UK)
organisation
the National Crime Agency
According to the National Crime Agency, within the last six months, there have been at least 2100 Lumma Stealer victims in the UK.
organisation
Australian Signals Directorate’s
Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)
organisation
Communications Security Establishment Canada’s
Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)
organisation
CSE
Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)
organisation
The Canadian Centre for Cyber Security
Canadian organizations
The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.
organisation
the Communications Security Establishment
Canadian organizations
The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.
organisation
Media Inquiries / Press Desk
Media Inquiries / Press Desk:
[email protected]
Australian organizations
Australian Signals Directorate
Visit
cyber.gov.au
or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.
organisation
Australian Signals Directorate
Visit
Media Inquiries / Press Desk:
[email protected]
Australian organizations
Australian Signals Directorate
Visit
cyber.gov.au
or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.
organisation
Object Identifiers
[
T1027
] containing Object Identifiers (OIDs) that instruct the SNMP agent on poorly configured networking devices to [
T1569
,
T1602.001
,
T1090
]:
Copy its configuration to a file, often called “config.bkp” or “output.txt”
If an attacker obtains a valid community string and gains successful SNMP access, they can use Object Identifiers (OIDs) to command the router to copy its configurations and send it via Trivial File Transfer Protocol (TFTP).
infrastructure
1.4.0
This advisory also uses MITRE DEFEND
TM
version 1.4.0.
organisation
DEFEND
This advisory also uses MITRE DEFEND
TM
version 1.4.0.
organisation
Config Copy
Example OIDs include:
1.3.6.1.4.1.9.9.96.1.1 (Cisco Config Copy)
1.3.6.1.4.1.9.9.96.1.1.1.1.5 (Config Copy Server Address, value for this OID is where the configuration file is being sent to)
organisation
SNMP Set-Requests
These scans, run via proxies, consist of SNMP Set-Requests from a spoofed IP address
organisation
D3-CH
[
D3-MAN
,
D3-MENCR
].
Use strong, unique passwords for local accounts on network devices and configure credentials to be stored securely to prevent reuse of compromised passwords [
D3-CH
].
organisation
MIB
[
3
]
Monitor and restrict access to SNMP OIDs using a Management Information Base (MIB) allow list
organisation
Access Control Lists
Use Access Control Lists (ACLs) to only allow management protocols, such as SNMP, from management devices, preferably on an out-of-band network.
organisation
Transmission Control Protocol
[
3
]
On edge firewalls and devices deny all external communications on the following ports unless mission critical, with strict monitoring if blocking is not feasible:
User Datagram Protocol (UDP) port 69 (TFTP)
Transmission Control Protocol (TCP) port 4786 (SMI
organisation
TCP
[
3
]
On edge firewalls and devices deny all external communications on the following ports unless mission critical, with strict monitoring if blocking is not feasible:
User Datagram Protocol (UDP) port 69 (TFTP)
Transmission Control Protocol (TCP) port 4786 (SMI
organisation
UDP
)
UDP ports 161 and 162 (SNMP)
TCP/UDP ports 10161 and 10162 (SNMPv3)
Update network device software and firmware images, especially to patch known vulnerabilities, and upgrade end-of-life devices to supported ones.
organisation
Cybersecurity Information Sheet Cisco
Cybersecurity Information Sheet Cisco Password Types: Best Practices. 2022.
organisation
d’information
Agenzia Informazioni
Footnotes
Národní úřad pro kybernetickou a informační bezpečnost
Forsvarets Efterretningstjeneste
Välisluureamet
Riigi Infosüsteem Amet
Sotilastiedustelu
Suojelupoliisi
Agence nationale de la sécurité des systèmes d’information
Agenzia Informazioni e Sicurezza Esterna
Agenzia Informazioni e Sicurezza Interna
Służba Kontrwywiadu Wojskowego
Nationellt Cybersäkerhetscenter
MITRE and ATT&CK are registered trademarks of The MITRE Corporation.
organisation
The MITRE Corporation
Footnotes
Národní úřad pro kybernetickou a informační bezpečnost
Forsvarets Efterretningstjeneste
Välisluureamet
Riigi Infosüsteem Amet
Sotilastiedustelu
Suojelupoliisi
Agence nationale de la sécurité des systèmes d’information
Agenzia Informazioni e Sicurezza Esterna
Agenzia Informazioni e Sicurezza Interna
Służba Kontrwywiadu Wojskowego
Nationellt Cybersäkerhetscenter
MITRE and ATT&CK are registered trademarks of The MITRE Corporation.
MITRE DEFEND is a trademark of the MITRE Corporation.
organisation
Disclaimer of Endorsement
Disclaimer of Endorsement
The information and opinions contained in this document are provided "as is" and without any warranties or guarantees.
organisation
Network Traffic Filtering
Network Traffic Filtering
D3-NTF
Use ACLs to only allow management protocols from management devices.
organisation
Network Vulnerability Assessment
Network Vulnerability Assessment
D3-NVA
Use an attack surface management service.
organisation
D3-NVA
Network Vulnerability Assessment
D3-NVA
Use an attack surface management service.
organisation
Microsoft 365
Hackers altered DNS settings on compromised MikroTik and TP-Link small office/home office (SOHO) routers to redirect authentication traffic to attacker-controlled servers and steal Microsoft 365 logins and OAuth tokens.
organisation
DNS
Hackers altered DNS settings on compromised MikroTik and TP-Link small office/home office (SOHO) routers to redirect authentication traffic to attacker-controlled servers and steal Microsoft 365 logins and OAuth tokens.
organisation
MikroTik
Hackers altered DNS settings on compromised MikroTik and TP-Link small office/home office (SOHO) routers to redirect authentication traffic to attacker-controlled servers and steal Microsoft 365 logins and OAuth tokens.
organisation
SOHO
Hackers altered DNS settings on compromised MikroTik and TP-Link small office/home office (SOHO) routers to redirect authentication traffic to attacker-controlled servers and steal Microsoft 365 logins and OAuth tokens.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
1.4.0
Software Version
Click for context!
This advisory also uses MITRE DEFEND
TM
version 1.4.0.
Metrics
infrastructure
18,000
Routers
Mitigation actions (FBI)
This advisory follows an international law enforcement operation that
disrupted FrostArmada
, a separate campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165, also tracked as Fancy Bear and Forest Blizzard) that had infected 18,000 routers across 120 countries by December 2025.
Metrics
infrastructure
Ios
Affected Product
In August 2025, the
FBI also warned
that the same group has been targeting critical infrastructure using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software (tracked as CVE-2018-0171) since November 2021.
Metrics
infrastructure
Microsoft 365
Affected Product
Hackers altered DNS settings on compromised MikroTik and TP-Link small office/home office (SOHO) routers to redirect authentication traffic to attacker-controlled servers and steal Microsoft 365 logins and OAuth tokens.
Intelligence Sources
CyberScoop
2026-07-13
CISA
2026-07-13
Infosecurity-Magazine
2026-07-13
Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns
Infosecurity-Magazine
BleepingComputer
2026-07-13
US and allies warn of Russian critical infrastructure attacks
BleepingComputer
Security Affairs
2026-07-15
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-21T12:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
71x
organisation
Identified Entity
APT Groups
entity
49x
attribution
Attributing Entity
the National Security Agency
authority
21x
tactic
MITRE ATT&CK Technique
T1584.008 - Network Devices
technique
15x
timeline
Temporal Reference
December 2025
date
14x
target region
Target Country
United States
country
12x
source region
Origin Country
Russian Federation
country
7x
industry
Targeted Sector
Defense
sector
5x
tactic
Cyber Operation Type
Reconnaissance
tactic
3x
threat actor
APT Group
Dragonfly
actor
2x
vulnerability
Exploited CVE
CVE-2018-0171
cve
2x
general metric
Italian Agency
7
italian agency
2x
general metric
+33
70
+33
2x
general metric
Port
69
port
2x
infrastructure
Affected Product
Ios
software
2x
general metric
%
54
%
Contextual Telemetry
Context Block
29 METRICS
general metric
Cyber Actors
16
cyber actors
general metric
Additional Countries
12
additional countries
general metric
Cve-2018
171
cve-2018
target region
Target Region
EUROPE
region
general metric
Individuals
24
individuals
general metric
Danish Intelligence Service
1
danish intelligence service
general metric
Estonian Intelligence Service
2
estonian intelligence service
general metric
System Authority
3
system authority
general metric
Defence Intelligence
4
defence intelligence
general metric
Service
5
service
general metric
French National Cybersecurity Agency
6
french national cybersecurity agency
general metric
Counterintelligence Service
9
counterintelligence service
general metric
Sweden National Cyber Security Centre
10
sweden national cyber security centre
general metric
Authoring - Sealing Agencies
11
authoring - sealing agencies
general metric
[email protected]
general metric
U.S. Code Sections
391
u.s. code sections
general metric
Cyber.Gov.Au
371
cyber.gov.au
general metric
Type
0
type
infrastructure
Software Version
1.4.0
version
general metric
Udp Ports
161
udp ports
general metric
Version
19
version
source region
Origin Region
EUROPE
region
general metric
Citizens
500,000
citizens
malware
Malware Payload
Lumma Stealer
tool
general metric
Lumma Stealer
2,100
lumma stealer
general metric
Other Agencies
15
other agencies
infrastructure
Routers
18,000
routers
general metric
Countries
120
countries
general metric
Logins
365
logins
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.