Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Network Security - Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns
Network Security Attacks Internet of Things Security Latest News News & Analysis Security

Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns

Kirsten DoyleBy Kirsten DoyleJuly 28, 20269 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
State attackers
Share
Facebook Twitter LinkedIn Email Copy Link
AI Summary

Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. .

SNMPv3 with authentication and encryption, disabling Smart Install, blocking TFTP externally, and cycling out end-of-life hardware are not complicated fixes, but they require someone to actually own that work inside the organisation, and that ownership gap is where the exposure lives.” . “I've personally been pulling router configs with Cisco Smart Install during penetration tests for years,” adds Denis Calderone, CTO of Suzu Labs. “One unauthenticated request to TCP 4786 and the switch hands over its startup config, credentials, SNMP community strings, TACACS+ keys, all of it.

And the second part of the story is also the same: the attackers are scanning for well-known vulnerabilities and using default or common credentials to access these systems.  . “The defensive posture remains the same: infrastructure operators must disable insecure protocols like Cisco’s Smart Install feature and SNMPv1 and v2, implement strong and unique passwords on all their devices, and restrict and monitor access to their management protocols.

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. 

The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors. 

According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk. 

The campaign is being tracked across the cybersecurity industry under several names, including Berserk Bear, Energetic Bear, Dragonfly, Ghost Blizzard, Crouching Yeti, and Static Tundra, although the agencies note that vendor attribution does not always align exactly. 

Attackers are abusing weak router configurations

Instead of relying on software vulnerabilities alone, the attackers are primarily exploiting insecure router configurations.

The advisory said the actors “primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation,” searching for internet-facing devices that expose Simple Network Management Protocol (SNMP) services using default or commonly known community strings. 

Once they have gained access, the attackers instruct affected devices to copy their configuration files before transferring them to infrastructure controlled by them, usually via TFTP. Those configuration files sometimes contain sensitive network information and credentials.

The agencies also said that while SNMP misconfigurations are the primary attack vector, the group has been observed exploiting known Cisco vulnerabilities, including CVE-2018-0171 and the legacy CVE-2008-4128 that affects end-of-life devices. 

Router hygiene is a weak point

The advisory argues that relatively straightforward security measures would go a long way towards reducing exposure.

Among its recommendations, the agencies advise businesses to:

  • Disable Cisco Smart Install.
  • Replace SNMPv1 and SNMPv2 with SNMPv3 using strong authentication and encryption.
  • Eliminate default community strings and use strong, unique passwords.
  • Restrict management protocols using access control lists.
  • Block unnecessary external access to SNMP, TFTP, and Smart Install ports.
  • Patch network devices regularly and replace end-of-life hardware. 

The advisory also recommends monitoring for anomalous local account activity and suspicious SNMP Set requests that might be a sign of reconnaissance or attempts to exfiltrate device configurations. 

“The authoring agencies strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers,” the advisory said. 

The joint advisory was issued by the NSA, CISA, FBI, the U.S. Department of Defence Cyber Crime Center, and cybersecurity agencies from Australia, Canada, the United Kingdom, New Zealand, and numerous European countries.

Networking devices remain a priority target

“Networking devices remain a priority target for Russian intelligence services because they offer a clear view of how an organisation operates,” adds Steven Weinstein, SVP of Intelligence, Flashpoint. “ Router and network configurations expose trusted relationships, communications paths, remote access, and the architecture supporting critical services. That operational intelligence helps an adversary map an environment, identify high-value opportunities, and maintain options for future collection or disruption. Communications infrastructure continues to draw sustained attention because it provides visibility that can support multiple objectives over time.”  

Steven Weinstein, SVP of Intelligence at Flashpoint, comments: “Law enforcement attention is increasingly focused on the infrastructure that enables cybercrime because that’s where many operations converge. The same hosting providers, brokers, and supporting services can facilitate activity for multiple threat actors over time. Disrupting those common dependencies has the potential to create broader operational friction than actions aimed at a single campaign or malware family.” 

The sector list matters less than the method

“The sector list matters less than the method,” says Aaron Warner, CEO of ProCircular. “These actors aren’t burning zero-days. They scan the internet for routers still answering on SNMPv1 or v2 with default or common community strings, then send the device an instruction to copy its own configuration to a file, often named config.bkp or output.txt, and ship it out over TFTP. That file hands them stored credentials and a map of your network. None of it touches an endpoint. The scan doesn’t check your industry before it checks your router. A hospital, a bank, a campus, and a plant floor with an aging edge switch all look the same to it.”

“Organisations have spent years investing in detection, yet sophisticated nation-state actors continue to find and exploit both old and new paths into operational environments,” adds Shane Fry, RunSafe Security. 

“As CISA noted, correcting poor configurations is an essential part of the response, but it is not enough. These actors are also exploiting common software vulnerabilities, and the recommended mitigations do not fully address how to make that software harder to exploit. Software hardening closes that gap by making it much more difficult for an attacker to turn a vulnerability into a working exploit. For critical infrastructure, that kind of built-in resilience is essential. The next evolution of cybersecurity is pairing detection and patching with mitigation that reduces the exploitability of the software itself.” 

The story isn’t the vulnerability itself

John Strand, Owner of Black Hills Information Security, says the story isn’t the vulnerability itself. “Attacking things like Cisco Smart Install or abusing SNMP isn’t new. Security teams have known about these techniques for more than a decade. The real story is that nation-state attackers continue to succeed by exploiting problems organisations should have fixed years ago. 

“Every time we see a large nation-state campaign, there’s a temptation to focus on the newest exploit or the most sophisticated technique. In reality, these campaigns are often built around vulnerabilities and insecure configurations that have been public knowledge for years. Attackers aren’t succeeding because defenders lack intelligence. They’re succeeding because too many organisations still struggle with the fundamentals of computer security.”

Strand’s biggest concern isn’t the technical details of this attack. “It’s that the organisations most at risk probably aren’t reading the advisories, following security news, or tracking CISA alerts. We spend a lot of time talking to security professionals who are already engaged, but the organisations that need the message most often aren’t part of that conversation. Until we find better ways to reach those organisations, attackers will continue to find easy wins using vulnerabilities we’ve known about for years.” 

Router infrastructure is consistently overlooked

Seemant Sehgal, Founder & CEO of BreachLock, adds: “Router infrastructure is one of the most consistently overlooked parts of an attack surface, and adversaries like FSB-linked actors know this. When you can pull a device config file over SNMP using the string ‘public’, you have a map of the internal network handed to you before you’ve done anything sophisticated. SNMPv3 with authentication and encryption, disabling Smart Install, blocking TFTP externally, and cycling out end-of-life hardware are not complicated fixes, but they require someone to actually own that work inside the organisation, and that ownership gap is where the exposure lives.” 

“I’ve personally been pulling router configs with Cisco Smart Install during penetration tests for years,” adds Denis Calderone, CTO of Suzu Labs. “One unauthenticated request to TCP 4786 and the switch hands over its startup config, credentials, SNMP community strings, TACACS+ keys, all of it. So, when the FBI warns that Russia’s FSB is doing the exact same thing against US critical infrastructure, the only thing that surprises me is that anyone still has this feature running. CVE-2018-0171 was patched in 2018 and Cisco has been telling people to disable Smart Install since 2017. It’s even been in the CISA KEV catalog since 2021. There just isn’t any excuse for this. 

“And then there’s SNMP exposed on the internet. Static Tundra is gaining initial access using community strings like “public” and “anonymous” with read-write permissions. What is SNMP doing exposed to the internet in 2026? SNMPv2 doesn’t even encrypt the community string. Once they’re in, they pull the config, harvest credentials, come back through SNMP or SSH, create privileged local accounts, modify TACACS+ to break remote logging, and in some cases deploy the SYNful Knock firmware implant that persists through reboots. By the time the device is fully compromised, its own audit trail is under the attacker’s control. And the FBI confirmed they’re doing ICS protocol reconnaissance after gaining access, which tells you exactly what they’re building toward. 

Run ‘no vstack’ on every Cisco switch in your environment today

Calderone says the fix is straightforward. “Run ‘no vstack’ on every Cisco switch in your environment today. If you don’t know whether Smart Install is enabled, assume it is, because it was enabled by default on older IOS releases. Disable SNMP on anything reachable from outside your management VLAN, and if you still need it, v3 with authentication and encryption is the minimum. If you’re running end-of-life gear that can’t accept the patch, those devices need to be on an active replacement plan, not a someday list. Static Tundra has maintained access to some environments for years without detection. Every day an unpatched router sits on your network with Smart Install enabled is another day the config is available to anyone who asks for it.” 

Infrastructure operators must disable insecure protocols

Doc McConnell, Head of Policy and Compliance at Finite State, says: “Over and over again, we see the same story playing out: infrastructure essential to public health and economic stability being successfully compromised by nation-state adversaries. Telecommunications, hospitals, state governments, energy infrastructure, and even the defence industrial base have all been under attack for over a decade. And the second part of the story is also the same: the attackers are scanning for well-known vulnerabilities and using default or common credentials to access these systems.
 
“The defensive posture remains the same: infrastructure operators must disable insecure protocols like Cisco’s Smart Install feature and SNMPv1 and v2, implement strong and unique passwords on all their devices, and restrict and monitor access to their management protocols. We have to do better. Our national security is at stake.”

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    One-click Claude Desktop flaw could enable hidden prompt injection and code execution
  • Kirsten Doyle
    Americans are ignoring scam calls, but phishing emails still fool many
  • Kirsten Doyle
    Sysdig uncovers first documented agentic ransomware operation
  • Kirsten Doyle
    AI-assisted software engineering is creating a new delivery paradox

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Major US telecom providers debut C2 ISAC to counter AI-driven threats

May 26, 20264 Mins Read

FCC Blocks Foreign-Made Routers, Citing National Security Risks

March 26, 20268 Mins Read

Cutting Into Overtime, Not Corners: How Network Automation Drives Business Value

March 13, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}