US and allies warn of Russian critical infrastructure attacks

Russian State Hackers Target Vulnerable Routers in Critical Infrastructure Networks

In a stark warning, cybersecurity agencies from the United States and nine other countries have jointly alerted that Russian state hackers are actively targeting vulnerable routers to infiltrate critical infrastructure networks. The threat, attributed to the Russian Federal Security Service (FSB) Center 16, poses a significant risk to sectors including energy, communications, defense industrial base, healthcare, financial services, defense, and state and local government services.

The joint advisory, co-authored by top US cybersecurity agencies such as the NSA, FBI, and CISA, along with international partners from Australia, the UK, Canada, New Zealand, Estonia, Finland, France, and Italy, highlights the tactics used by hackers. These attackers scan internet-connected IP address ranges for routers accepting default or common Simple Network Management Protocol (SNMP) authentication strings. They then use spoofed IP addresses to issue commands that allow them to copy device configuration files and exfiltrate them via the Trivial File Transfer Protocol (TFTP) to actor-controlled servers.

This is not a new threat – in August 2025, the FBI issued a warning about the same group targeting critical infrastructure using a vulnerability in Cisco IOS and Cisco IOS XE software. However, the latest advisory emphasizes that the hackers have been scanning for vulnerable routers and exploiting known vulnerabilities related to SNMP, making it crucial for network defenders to take immediate action.

The sectors at greatest risk are those with outdated or poorly configured networks, which can be easily compromised by these attacks. “Centre 16 has been seen hunting for vulnerable routers by scanning the internet for devices that still use default or weak SNMP passwords and community strings,” warns the UK National Cyber Security Centre. To mitigate this threat, cybersecurity experts recommend upgrading to SNMPv3, disabling Cisco Smart Install, enforcing strong unique passwords, blocking TFTP and SNMP traffic at edge firewalls, updating software and firmware, and replacing end-of-life devices.

This warning follows a recent international operation that disrupted FrostArmada, another campaign attributed to APT28 (a Russian military intelligence group linked to GRU unit 26165). The operation, supported by the US Department of Justice, Polish government, and multiple cybersecurity companies, remotely removed malicious DNS settings from compromised routers and forced them to connect to legitimate DNS resolvers.

As the threat landscape continues to evolve, it’s essential for security teams to stay vigilant. Regular testing and updating of network defenses can help prevent these types of attacks. Remember that no system is completely secure – hackers will always look for vulnerabilities. Test every layer before they do.


Source: Bleeping Computer — 2026-07-13