📣 Send us your press release
Site updates every 15 minutes
Technology

FSB Center 16 Exploits Routers Via SNMP and Cisco Smart Install

A Russian FSB signals-intelligence unit, FSB Center 16 (also known as Static Tundra), has been exploiting misconfigured routers using SNMP and Cisco Smart Install for over a decade to gather intelligence on critical infrastructure. A warning about these tactics was issued in July 2026.

25 July 2026
FSB Center 16 Exploits Routers Via SNMP and Cisco Smart Install
Image is an AI-generated illustration

A Russian state-sponsored actor, identified as FSB Center 16 and tracked under aliases including Static Tundra, has been systematically compromising network devices, primarily routers, through simple yet effective methods for over ten years. Cybersecurity firm Picus Security highlighted in an analysis that the group's primary technique does not rely on novel exploits but rather on locating and abusing poorly secured internet-facing devices.

The core of the campaign involves scanning the internet for SNMP agents that accept default or weak community strings. Attackers then utilize SNMP Set-Requests to abuse the CISCO-CONFIG-COPY-MIB functionality within Cisco devices. This allows them to copy the device's configuration to an attacker-controlled server via TFTP. In some instances, the group has also leveraged known vulnerabilities such as CVE-2018-0171 (Cisco Smart Install) and the end-of-life CVE-2008-4128.

FSB Center 16 is described as the signals-intelligence arm of Russia's Federal Security Service (FSB). Security vendors track the same activities under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, and Ghost Blizzard. Unlike Russian GRU-linked groups focusing on disruption, this unit's focus is espionage and intelligence gathering.

In July 2026, a joint advisory from US agencies like the NSA, CISA, and FBI, along with international partners, warned organizations about these persistent threats. The advisory recommended disabling Cisco Smart Install, migrating to SNMPv3 with strong authentication and privacy, blocking SNMPv1/v2c, updating Cisco password hashing, and restricting TFTP, SMI, and SNMP at network perimeters. Picus Security emphasizes the importance of validating these security controls through continuous breach and attack simulations to ensure effective defense against such persistent threats.

Original source: picussecurity.com