The US and 11 allied nations issued a joint advisory warning that Russian state-sponsored threat actors are systematically targeting networking devices, primarily routers, across critical infrastructure sectors worldwide including communications, defense, energy, and space systems.
The advisory, authored by agencies from the US, Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, Italy, New Zealand, Poland, Sweden, and the UK, attributes the activity to Russian Federal Security Service (FSB) Center 16. Multiple tracked groups including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra are linked to the campaign.
Using proxies, the threat actors send Simple Network Management Protocol (SNMP) set-requests to IP ranges, instructing SNMP agents on target devices to copy configurations to a remote server via TFTP. They have also been observed exploiting known Cisco vulnerabilities including CVE-2018-0171 to achieve arbitrary code execution on compromised devices.
For organizations in the space sector, the threat is particularly acute. Satellite ground stations, tracking facilities, and communication backbones rely heavily on routers and network infrastructure that, if compromised, could allow attackers to intercept telemetry, disrupt command links, or pivot deeper into operational networks.
The advisory notes that many tactics, techniques, and procedures overlap with activity by other malicious cyber actors such as Salt Typhoon, making attribution and detection more challenging for defenders.
Network defenders are advised to disable Cisco Smart Install on all devices, upgrade from SNMPv1 and SNMPv2 to SNMPv3 with modern encryption, use unique credentials for network device accounts, and restrict access to SNMP Object Identifiers. The NSA separately published guidance on reducing the risk of SNMP abuse.
Keeping network device software and firmware updated remains the most effective defense against exploitation of known vulnerabilities.