Cybersecurity agencies from the United States and eight allied countries have warned that Russian state-backed hackers are actively targeting vulnerable network routers to gain access to critical infrastructure.
The attackers focus on poorly secured devices, using weak configurations to steal network data and expand their access inside sensitive environments.
Russian Hackers Scan Routers for Weak Security
Cybersecurity and intelligence agencies from the United States, Australia, the United Kingdom, Canada, New Zealand, Estonia, Finland, France, and Italy jointly released the advisory.
Investigators linked the campaign to hackers connected to Russia’s Federal Security Service (FSB) Center 16.
Security researchers track the group under several names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra.
The attackers scan internet-facing IP addresses for routers that still rely on default or weak Simple Network Management Protocol (SNMP) community strings.
After finding a vulnerable device, they send spoofed requests to copy router configuration files. They then transfer the stolen files to attacker-controlled servers through the Trivial File Transfer Protocol (TFTP).
Critical Infrastructure Remains the Main Target
The hackers primarily target organizations that operate critical infrastructure.
Industries facing the highest risk include:
- Energy
- Communications
- Defense
- Defense industrial base
- Healthcare
- Financial services
- State and local government
By compromising routers, the attackers can map internal networks, collect sensitive information, and prepare additional attacks.
Hackers Continue Exploiting Cisco Vulnerabilities
The agencies also warned that the same group continues to exploit the CVE-2018-0171 vulnerability in Cisco Smart Install.
According to the advisory, the hackers have abused the flaw since late 2021 to compromise vulnerable Cisco IOS and Cisco IOS XE devices.
In addition to weak SNMP settings, the group exploits Cisco Smart Install and known web management flaws to seize control of network devices.
Agencies Urge Organizations to Strengthen Security
The advisory encourages organizations to improve router security without delay.
Recommended actions include:
- Upgrade to SNMPv3.
- Disable Cisco Smart Install if it is unnecessary.
- Create strong, unique administrator passwords.
- Block SNMP and TFTP traffic at network boundaries where appropriate.
- Install the latest software and firmware updates.
- Replace unsupported or end-of-life networking equipment.
These steps significantly reduce the chances of unauthorized access.
Warning Follows Global Router Cleanup Operation
The advisory follows an international law enforcement operation that disrupted a separate Russian-linked campaign affecting approximately 18,000 routers across 120 countries.
During that campaign, attackers changed DNS settings on vulnerable MikroTik and TP-Link routers. They redirected authentication traffic through servers they controlled and stole Microsoft 365 credentials and OAuth tokens.
Authorities later removed the malicious DNS settings from compromised routers during a court-approved operation. They also restored the affected devices to legitimate DNS services, preventing the attackers from continuing to intercept authentication traffic.


0 responses to “Russian Router Attacks Target Critical Infrastructure, Agencies Warn”