Executive Summary
In July 2026, a joint advisory from the NSA, CISA, FBI, and international partners highlighted that Russian FSB Center 16 cyber actors, also known as Berserk Bear and Dragonfly, have been exploiting poorly configured and vulnerable networking devices worldwide. These actors primarily target critical infrastructure sectors such as communications, energy, defense, financial services, government facilities, and healthcare. Their tactics include scanning for devices with default or weak SNMP credentials and exploiting known vulnerabilities in Cisco devices and protocols, enabling unauthorized access and potential disruption of essential services.
This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure through common vulnerabilities. Organizations are urged to enhance their network security by updating device configurations, disabling legacy protocols, and implementing strong authentication measures to mitigate such risks.
Why This Matters Now
The continued exploitation of vulnerable routers by Russian state-sponsored actors highlights the urgent need for organizations to strengthen their network defenses. With critical infrastructure at risk, immediate action is essential to prevent potential disruptions and safeguard sensitive information.
Attack Path Analysis
Russian FSB Center 16 cyber actors exploited vulnerable routers in critical infrastructure sectors by scanning for devices with default SNMP community strings, gaining initial access. They escalated privileges by exploiting known vulnerabilities like CVE-2018-0171 in Cisco devices. The actors moved laterally within networks by leveraging compromised routers to access internal systems. They established command and control by using compromised devices to proxy their traffic, maintaining persistent access. Exfiltration was conducted by transferring configuration files via TFTP to attacker-controlled servers. The impact included unauthorized access to sensitive information and potential disruption of critical services.
Kill Chain Progression
Initial Compromise
Description
Russian FSB Center 16 cyber actors exploited vulnerable routers in critical infrastructure sectors by scanning for devices with default SNMP community strings, gaining initial access.
Related CVEs
CVE-2018-0171
CVSS 9.8A vulnerability in the Smart Install feature of Cisco IOS and IOS XE Software allows unauthenticated, remote attackers to execute arbitrary code or cause a denial of service via crafted Smart Install messages.
Affected Products:
Cisco IOS – 15.2(5)e
Cisco IOS XE – Unknown
Exploit Status:
exploited in the wildCVE-2008-4128
CVSS 4.3Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via crafted requests.
Affected Products:
Cisco IOS – 12.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Active Scanning: Scanning IP Blocks
Active Scanning: Vulnerability Scanning
Exploit Public-Facing Application
System Services
Exploitation for Privilege Escalation
OS Credential Dumping
Data from Configuration Repository: SNMP (MIB Dump)
Exfiltration Over Alternative Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical router infrastructure targeted by Russian FSB Center 16 requiring immediate SNMP hardening, encrypted traffic capabilities, and zero trust segmentation implementation.
Utilities
Energy sector networks vulnerable to lateral movement attacks through compromised networking devices, demanding east-west traffic security and egress policy enforcement.
Government Administration
State and local government facilities specifically targeted, requiring multicloud visibility, threat detection capabilities, and compliance with NIST cybersecurity framework standards.
Financial Services
Banking infrastructure exposed to nation-state APT exploitation via poorly configured routers, necessitating PCI compliance adherence and anomaly response systems.
Sources
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targetinghttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194aVerified
- Cisco Security Advisory: Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerabilityhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit vulnerable routers, escalate privileges, and move laterally within the network, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit routers with default SNMP community strings would likely be constrained, limiting their initial access points.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges through known vulnerabilities would likely be constrained, reducing their control over compromised devices.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, limiting their access to internal systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, reducing their persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data via TFTP would likely be constrained, limiting unauthorized data transfers.
The attacker's ability to access sensitive information and disrupt services would likely be constrained, reducing the overall impact.
Impact at a Glance
Affected Business Functions
- Network Operations
- Data Transmission
- Remote Access Services
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of network configurations and sensitive data transmitted through compromised routers.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Encrypted Traffic (HPE) to secure data in transit and prevent unauthorized access.
- • Deploy East-West Traffic Security to monitor and control lateral movement within the network.
- • Utilize Zero Trust Segmentation to enforce least privilege access and limit attacker mobility.
- • Enhance Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Egress Security & Policy Enforcement to restrict unauthorized data exfiltration and command and control communications.



