Russian State-Sponsored Hackers Exploit Weak Network Security to Gain Access to Critical Infrastructure Worldwide
A joint advisory from US cybersecurity agencies and their counterparts in a dozen allied countries has revealed that state-sponsored threat actors affiliated with Russia’s Federal Security Service (FSB) Center 16 continue to compromise weakly protected routers and other networking equipment to gain access to critical infrastructure networks worldwide. This ongoing issue has impacted organizations in the defense industrial base, energy, financial services, government, and healthcare sectors for years.
The advisory highlights the importance of basic router hygiene as a means for companies and organizations to deter state-level cyber actors. It also coincides with news of the United Kingdom and the European Union imposing sanctions on 24 Russian individuals and entities for their role in orchestrating cyberattacks across Europe and the UK, for election interference, and Ukraine-related disinformation campaigns. The list of those sanctioned includes senior officials in Russia’s military intelligence agency (GRU), cybercriminal proxies, and organizations accused of supporting Russian cyber operations and influence campaigns.
The joint advisory on the Russian attacks targeting insecure routers and other networking gear builds on an FBI advisory last year on the same threat. It offers a detailed look at the tactics that FSB Center 16 actors use to gain access to targeted environments. The most common method, according to the advisory, is for the actors to scan for exposed SNMP services that accept factory-default or easily guessed passwords. They then instruct compromised devices to export their configuration files to attacker-controlled servers using Trivial FTP (TFTP) or FTP.
The threat actors also exploit known Cisco vulnerabilities and misuse Cisco Smart Install (SMI) for initial access, the agencies added. From a risk mitigation standpoint, critical infrastructure organizations should disable Cisco Smart Install and swap out SNMPv1 for v2c SNMPv3, which offers stronger authentication and encryption support. The authoring agencies also want organizations to replace default passwords with strong, unique ones for all network devices, monitor SNMP Set requests and unusual local account activity, use access control lists, and block unneeded TFTP, SNMP, and Smart Install traffic at network boundaries.
This is the first time that the UK and the EU have jointly sanctioned Russian state actors and their proxies for cyberattacks and other malicious activities in the region. The latest sanctions bring to 3,400 the number of individuals and entities that the UK has sanctioned so far in connection with Russia’s war in Ukraine. The joint advisory serves as a reminder of how state actors continue to succeed by exploiting problems that organizations are well aware of and should have addressed years ago.
Practically speaking, this means that organizations must prioritize basic router security hygiene, including replacing default passwords, monitoring SNMP traffic, and blocking unnecessary services. By doing so, they can significantly reduce the risk of being targeted by state-sponsored threat actors. Furthermore, it’s essential for critical infrastructure organizations to stay up-to-date with the latest security patches and updates for their networking equipment, as well as to implement robust access controls and logging mechanisms to detect potential security incidents early on.
Source: Dark Reading — 2026-07-13