Russian State-Sponsored Hackers Continuously Exploit Weak Security Practices Globally
A joint advisory issued by US cybersecurity agencies and their international counterparts has shed light on an ongoing issue where Russian state-sponsored hackers are compromising routers and other networking equipment to gain access to critical infrastructure networks worldwide. The advisory, which marks a significant development in the global response to cyber threats, highlights the importance of basic router hygiene in deterring state-level cyber actors.
The hackers, affiliated with Russia’s Federal Security Service (FSB) Center 16, have been targeting weakly protected routers and networking equipment using techniques that include scanning for exposed Simple Network Management Protocol (SNMP) services with default or easily guessed passwords. Once inside, they instruct compromised devices to export their configuration files to attacker-controlled servers using Trivial FTP (TFTP) or File Transfer Protocol (FTP). These tactics are not new, but the advisory serves as a stark reminder of how state-sponsored actors continue to succeed by exploiting problems that organizations should have addressed years ago.
The UK and EU’s recent imposition of sanctions on 24 Russian individuals and entities for their role in orchestrating cyberattacks across Europe and the UK underscores the severity of this issue. The list of those sanctioned includes senior officials in Russia’s military intelligence agency (GRU), cybercriminal proxies, and organizations accused of supporting Russian cyber operations and influence campaigns. The joint sanctions are a significant escalation in the global response to Russian state-sponsored hacking and demonstrate the international community’s commitment to holding perpetrators accountable.
The advisory issued by US agencies highlights the importance of basic router security hygiene in deterring state-level cyber actors. It recommends that organizations replace default passwords with strong, unique ones for all network devices, monitor SNMP Set requests and unusual local account activity, use access control lists, and block unneeded TFTP, SNMP, and Smart Install traffic at network boundaries. These recommendations are not new, but they serve as a stark reminder of how easily compromised routers can be used as a foothold for more sophisticated attacks.
The issue is further complicated by the fact that many organizations in critical infrastructure sectors such as defense industrial base, energy, financial services, government, and healthcare are still vulnerable to these types of attacks. These sectors have been repeatedly warned about the risks associated with weak security practices, but it seems that not enough has been done to address these issues.
In conclusion, the joint advisory and sanctions serve as a stark reminder of the importance of basic router hygiene in deterring state-level cyber actors. Organizations in critical infrastructure sectors must take immediate action to secure their networks by implementing the recommended best practices outlined in the advisory. This includes replacing default passwords with strong, unique ones for all network devices, monitoring SNMP Set requests and unusual local account activity, using access control lists, and blocking unneeded TFTP, SNMP, and Smart Install traffic at network boundaries. Only by taking these steps can organizations hope to mitigate the risk of compromise by state-sponsored hackers.
Source: Dark Reading — 2026-07-13