US and allies warn of Russian critical infrastructure attacks

Russian State Hackers Target Critical Infrastructure, Warns Global Cybersecurity Community

A joint warning issued by cybersecurity agencies from the US and eight other countries has sounded the alarm on a sophisticated hacking campaign targeting critical infrastructure networks worldwide. The attackers, attributed to Russia’s Federal Security Service (FSB) Center 16, are exploiting poorly configured routers to gain access to sensitive systems.

The hackers use a technique called scanning to identify vulnerable devices that still rely on default or weak Simple Network Management Protocol (SNMP) passwords and community strings. They then issue commands using spoofed IP addresses to copy device configuration files and exfiltrate them via the Trivial File Transfer Protocol (TFTP) to actor-controlled servers.

The sectors most at risk from these attacks include energy, communications, defense industrial base, healthcare, financial services, defense, and state and local government services. The fact that critical infrastructure is being targeted is particularly concerning, as it could have far-reaching consequences for public safety and national security.

This warning follows a similar alert issued by the FBI in August 2025, which highlighted the same group’s use of a critical vulnerability in Cisco’s Smart Install feature to gain control of network devices. The hackers are known to exploit well-known vulnerabilities relating to Cisco devices and web-portal flaws to compromise networks.

To mitigate these attacks, cybersecurity experts recommend upgrading to SNMPv3, disabling Cisco Smart Install, enforcing strong unique passwords, blocking TFTP and SNMP traffic at edge firewalls, updating software and firmware, and replacing end-of-life devices. These measures are crucial in hardening networks against the relentless scanning efforts of these state-sponsored hackers.

The international law enforcement operation that disrupted FrostArmada, a separate campaign attributed to APT28 (a Russian military intelligence group), is a stark reminder of the threat posed by nation-state actors. In this operation, the FBI remotely removed malicious DNS settings from compromised routers and forced them to connect to legitimate DNS resolvers.

As we navigate an increasingly complex cybersecurity landscape, it’s essential for security teams to stay vigilant and test their defenses regularly. With the majority of successful attacks going undetected until after the fact, it’s crucial to prioritize breach and attack simulation testing to ensure that SIEM and EDR rules are effective in detecting threats.

In conclusion, the latest warning from global cybersecurity agencies serves as a stark reminder of the importance of staying one step ahead of sophisticated hackers. By taking proactive measures to harden our networks and test our defenses regularly, we can reduce the risk of successful attacks and protect critical infrastructure from falling victim to these relentless scanning efforts.


Source: Bleeping Computer — 2026-07-13