INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russian APT Groups Target Network Devices

| 2026-07-15 18:59 CRITICAL HIGH
Executive Summary AI-generated
The Russian Federal Security Service's (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. These sophisticated threat groups mainly target routers by scanning the internet for exposed Simple Network Management Protocol (SNMP) services with weak or default credentials. Their techniques overlap with other nation-state actors, making it essential for organizations to monitor SNMP activity, restrict management access through Access Control Lists (ACLs), block unnecessary ports such as TFTP, SMI and SNMP from external networks, and detect suspicious configuration changes to defend against multiple threats.
Technical Mitigations AI-generated
* Disabling Cisco Smart Install and replacing SNMPv1/v2 with SNMPv3 using strong encryption can help secure network devices against Russian APT groups. * Enforcing unique passwords, securing storage, monitoring SNMP activity, restricting management access through ACLs, blocking unnecessary ports such as TFTP, SMI, and SNMP from external networks, and keeping firmware updated are recommended measures to strengthen router security. * Using attack surface management tools can help identify exposed systems and weak configurations in critical infrastructure sectors. * Replacing unsupported devices and monitoring for suspicious configuration changes is essential to prevent further attacks by Russian hackers.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt TyphoonDragonflyDragonflyAPT28APT28 Lumma StealerLumma Stealer CVE-2008-4128CVE-2008-4128 CVE-2018-0171CVE-2018-0171
Target & Sectors
NORDICS NORDICS EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA healthhealth governmentgovernment healthcarehealthcare financefinance mediamedia energyenergy defensedefense
Incident Timeline
‎November 2021
Russian hackers used a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software to target vulnerable routers worldwide.
attribution CVE-2018-0171
attribution FBI
infrastructure Ios
attribution Smart Install
attribution Cisco IOS
‎late 2025
Threat actors used FSB Center 16 to target Poland's energy grid in late 2025.
general_metric 16 cyber actors
industry Energy
target_region Poland
target_region United Kingdom
source_region EUROPE
organisation EU
organisation UK Blame
organisation European Union
‎August 2025
The FBI warned that Russian hackers targeted vulnerable routers worldwide using a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software.
attribution CVE-2018-0171
attribution FBI
infrastructure Ios
attribution Smart Install
attribution Cisco IOS
‎December 2025
Russian Hackers Disrupted FrostArmada's Campaign to Infect 18,000 Routers Worldwide.
target_region Russian Federation
industry Energy
target_region Poland
target_region EUROPE
organisation the European Union
attribution FBI
attribution FrostArmada
threat_actor APT28
attribution GRU
attribution Fancy Bear
infrastructure 18,000 routers
general_metric 120 countries
‎July 13
Russian hackers used compromised routers to target the UK government and 500,000 citizens worldwide.
industry Government
target_region United Kingdom
general_metric 500,000 citizens
‎2026/07/15
Russian hackers targeted vulnerable routers worldwide using spoofed requests to steal device configurations and move them to attacker-controlled servers via Trivial File Transfer Protocol (TFTP).
organisation APT Groups
organisation APT
organisation CVE-2018-0171
organisation SMI
organisation the Russian FSB Center
organisation CVE-2018
organisation CSA
organisation Russian State Hackers Target
organisation TFTP
organisation Initial Access Technique Title ID
organisation Collect
organisation SNMP
organisation Command
organisation C2
organisation Cybersecurity Services
organisation Defense Federal Acquisition Regulation Supplement
organisation DFARS
organisation Russian Federal Security Service
organisation the Russian Federal Security Service Center
organisation Simple Network Management Protocol (
organisation Smart Install
organisation Center
organisation National Cyber Security Centre
threat_actor Dragonfly
organisation Berserk Bear
organisation IP
organisation the Trivial File Transfer Protocol
organisation Groups
organisation FTP
organisation Trivial File Transfer Protocol
organisation VPS
threat_actor Salt Typhoon
organisation ACLs
organisation New Zealand National Cyber Security Centre
organisation United Kingdom National Cyber Security Centre
organisation the National Crime Agency
organisation Australian Signals Directorate’s
organisation Communications Security Establishment Canada’s
organisation CSE
organisation The Canadian Centre for Cyber Security
organisation the Communications Security Establishment
organisation Media Inquiries / Press Desk
organisation Australian Signals Directorate Visit
organisation Object Identifiers
infrastructure 1.4.0
organisation DEFEND
organisation Config Copy
organisation SNMP Set-Requests
organisation D3-CH
organisation MIB
organisation Access Control Lists
organisation Transmission Control Protocol
organisation TCP
organisation UDP
organisation Cybersecurity Information Sheet Cisco
organisation d’information Agenzia Informazioni
organisation The MITRE Corporation
organisation Disclaimer of Endorsement
organisation Network Traffic Filtering
organisation Network Vulnerability Assessment
organisation D3-NVA
organisation Microsoft 365
organisation DNS
organisation MikroTik
organisation SOHO
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎1.4.0
Software Version
Metrics
infrastructure
18,000
Routers
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Microsoft 365
Affected Product