Back Techtimes FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years
A Russian intelligence unit that has been quietly stealing network maps from critical infrastructure operators around the world — not through sophisticated zero-day exploits, but through factory-default passwords on routers that organizations never changed — was formally named and sanctioned Monday in the most coordinated Western cyber attribution action since the invasion of Ukraine. The vulnerability at the center of the campaign is not new: SNMPv3, the protocol version that would close the attack's main entry point, has existed since 2002. Two-plus decades of deferred maintenance left the door open.
Thirteen nations co-sealed a joint cybersecurity advisory Monday naming FSB Center 16 — the Russian Federal Security Service unit also tracked by security companies as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra — as the actor behind sustained intrusions into energy, communications, defense industrial, healthcare, financial, and government networks worldwide. The advisory, published simultaneously with a UK-EU sanctions package targeting 24 individuals and entities tied to Russian cyber and hybrid operations, paired the threat disclosure with a formal attribution of the December 2025 attack on Poland's energy grid to the same unit. That attack failed, but the UK government said it could have left 500,000 people without electricity in the depths of winter.
FSB Center 16's operational history predates the current advisory by years. The unit, working under aliases that reflect different researchers tracking the same underlying activity, compromised industrial and energy targets in Europe and North America as far back as 2013 under the Dragonfly campaign name. By 2015, it had deployed SYNful Knock — a firmware-level implant that survived router reboots by replacing legitimate Cisco firmware images — across compromised network devices, providing persistent covert access that continued undetected in some environments for extended periods, as Mandiant documented in its original SYNful Knock research .
The 2022 US Department of Justice indictment formally established the link between Energetic Bear and FSB Center 16. By November 2021, the same unit had begun exploiting CVE-2018-0171 , a critical Cisco Smart Install vulnerability carrying a CVSS score of 9.8 — a flaw Cisco patched in March 2018. Center 16 was using a three-year-old patch to access devices whose administrators had not applied it, as the FBI confirmed in a public service announcement last August .
The NSA's statement on the advisory was blunt: "This is an ongoing issue that has impacted various US and foreign networks across multiple sectors."
The attack technique Center 16 uses most often is not a vulnerability in the conventional sense. It is a configuration failure — and that distinction matters.
The Simple Network Management Protocol (SNMP) is a decades-old standard used by network engineers to monitor and manage routers, switches, and other networked devices remotely. Versions 1 and 2c of the protocol authenticate management sessions using a "community string" — a shared password that is transmitted across the network in plaintext. Any device positioned between the attacker and the target router, including the attacker's own scanning infrastructure, can read that string. SNMPv1 was standardized in 1988. SNMPv3 — which introduced per-user authentication using keyed hashing and optional encryption — was standardized in 2002.
Center 16 scans the open internet for routers that still respond to default or commonly known SNMP community strings — passwords like "public" or "private" that ship on devices and are never changed. Once the unit identifies a router that accepts those strings, it issues SNMP commands using a spoofed IP address to copy the device's configuration file, then directs the router to send that file to an attacker-controlled server using TFTP, the Trivial File Transfer Protocol, according to the NSA joint router hygiene advisory .
A router's configuration file is an extraordinarily complete document. It contains the device's full network architecture: subnet assignments, routing tables, VLAN configurations, firewall rules, and stored credentials. For an intelligence operation trying to understand a target organization's internal network without triggering intrusion detection systems, a configuration file obtained through a legitimate-looking SNMP query is more valuable than most pieces of malware could provide — and far less likely to be detected.
The exploitation of TFTP illustrates the attack's elegance. TFTP has no authentication and no encryption by design; it was built for network-boot scenarios where simplicity mattered more than security. Organizations that have never restricted outbound TFTP traffic at their network perimeter leave themselves exposed to a router that the attacker has commanded to reach out and deliver its own configuration data. The router is not compromised in the traditional sense — it is simply following an authenticated (via the community string) management instruction. That is what makes the attack so durable.
Configuration file theft is reconnaissance, not the end goal. The advisory describes a second phase: on some compromised devices, Center 16 modified the configuration files to create unauthorized access, establishing a foothold for deeper network penetration. The FBI confirmed that reconnaissance on compromised networks revealed the unit's interest in protocols and applications associated with industrial control systems — suggesting infrastructure mapping as a precursor to potential disruptive operations.
The December 2025 Poland energy grid attack, now formally attributed to FSB Center 16 by the UK and EU, represents the type of operation that reconnaissance of this kind is intended to enable. UK Foreign Secretary Yvette Cooper described the Poland attack in unambiguous terms, saying the Russian state was "striking Poland's energy grid in the depths of winter" as part of what she characterized as "increasingly reckless attempts to sow chaos across Europe." The attack failed; the 500,000 civilians potentially affected did not lose power. The advisory context makes clear that network access enabling such an attempt was obtained through exactly the kind of quiet router reconnaissance the advisory describes.
The EU High Representative for Foreign Affairs, Kaja Kallas, confirmed Monday that FSB Center 16 has also been conducting cyber espionage operations targeting strategic French government entities since 2010 — underscoring that the unit's infrastructure access campaigns span multiple countries and decades.
In addition to SNMP community string scanning, Center 16 has also actively exploited CVE-2018-0171, the Cisco Smart Install vulnerability . Smart Install is a plug-and-play switch configuration feature in Cisco IOS and IOS XE software. The vulnerability — caused by improper validation of packet data — allows an unauthenticated remote attacker to send a crafted message to TCP port 4786 and execute arbitrary code or crash the device. Cisco patched CVE-2018-0171 in March 2018. FSB Center 16 was still exploiting it on unpatched and end-of-life devices as recently as last year, according to Cisco Talos, which tracks the same group under the alias Static Tundra .
Cisco Talos assesses that Static Tundra is a likely sub-cluster of Energetic Bear/Berserk Bear based on overlapping tactics, techniques, and procedures, corroborated by the FBI. The unit has demonstrated advanced knowledge of network device internals and bespoke tooling — including the SYNful Knock firmware implant first reported in 2015 — that places it in the top tier of network-intrusion specialists among known threat actors.
The advisory also notes that the unit's techniques overlap with those used by China-linked threat actor Salt Typhoon — a signal that the SNMP and configuration-file-exfiltration playbook is not proprietary to Russia and that the mitigations listed below address a broader class of threat.
Monday's advisory sits alongside a parallel campaign that Western governments spent months disrupting before today's disclosure. In April 2026, an international law enforcement operation — backed by the FBI, DOJ, Poland, and several private cybersecurity companies — dismantled FrostArmada , a campaign attributed to APT28, a separate Russian intelligence unit tied to GRU Unit 26165 rather than the FSB.
APT28 had compromised approximately 18,000 MikroTik and TP-Link small office/ office routers across 120 countries, altering their DNS settings to redirect authentication traffic to attacker-controlled servers in order to steal Microsoft 365 logins and OAuth tokens. Unlike Center 16's SNMP-based approach, FrostArmada required no malware on the victim's laptop or the company's mail server — only a redirected DNS setting on a or small-office router that the victim's household devices trusted implicitly.
The FBI's court-authorized operation remotely removed the malicious DNS configurations and reconnected compromised devices to legitimate resolvers. At its December 2025 peak, FrostArmada had infected more than 18,000 unique IP addresses, with over 200 named organizations and 5,000 consumer devices confirmed as victims — primarily government ministries, law enforcement agencies, and IT providers across North Africa, Central America, Southeast Asia, and Europe, as documented in the Lumen Black Lotus Labs FrostArmada campaign report .
Taken together, the two campaigns reveal a coherent Russian strategic doctrine: treat the perimeter of internet-exposed network devices as a persistent intelligence-collection platform. Routers sit at the exact boundary between the public internet and internal networks, are rarely included in security audit cycles, and often run for years without firmware updates or credential rotation. Both campaigns exploited that neglect — one through a management protocol deficiency that has been fixable since 2002, the other through administrative passwords that users never changed.
The advisory pairs its threat disclosure with a concrete mitigation list, and the urgency in its language reflects the fact that most of the recommended actions are configurations, not patches — meaning organizations can reduce their exposure immediately.
The NCSC's Jonathon Ellison, Director of National Resilience, said the advisory "provides decisive, actionable directions from the global security community that network defenders should implement" and specifically urged organizations "entrusted with UK critical networks to adopt these recommended measures immediately."
The specific actions the advisory calls for:
Upgrade to SNMPv3. Versions 1 and 2c transmit community strings in plaintext and offer no authentication against spoofed sources. SNMPv3 provides per-user authentication using keyed HMAC hashing and optional AES encryption of management traffic. Organizations still running v1 or v2c on internet-reachable devices should treat this upgrade to SNMPv3 guidance as the highest-priority action.
Disable Cisco Smart Install. If the feature is not actively in use, it should be turned off. CVE-2018-0171 can only be exploited when the Smart Install client feature is enabled. Cisco's own guidance from 2018 recommended disabling Smart Install on any device where it is not operationally necessary.
Replace default and weak community strings immediately. SNMP community strings should be treated as passwords: complex, unique, rotated on a regular schedule, and never left at factory defaults ("public," "private," "community").
Block SNMP and TFTP at edge firewalls. Neither protocol should be accessible from the public internet. SNMP management traffic should travel on dedicated out-of-band management networks with access control lists restricting which hosts can issue management queries. TFTP traffic should be blocked outbound at the perimeter.
Retire end-of-life equipment. Devices that no longer receive security updates from their manufacturers cannot be patched against newly discovered vulnerabilities. Replacing end-of-life routers and switches removes the attack surface the advisory describes.
Apply all available patches , including CVE-2018-0171 and related Cisco IOS flaws, and audit firmware currency across the entire network device inventory.
The NCSC also encouraged organizations to pursue NCSC Cyber Essentials certification and to use the updated Cyber Assessment Framework to evaluate their security maturity and resilience against this class of threat.
The full NSA router hygiene advisory is available at media.defense.gov. The NCSC companion advisory is available at ncsc.gov.uk.
FSB Center 16 is the 16th Center of Russia's Federal Security Service — the unit responsible for signals intelligence and foreign cyber targeting. It has been active since at least 2010 and is tracked by cybersecurity companies under different names — Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra — because different research teams independently identified the same underlying activity and assigned their own labels before the connections became clear. The 2022 US Department of Justice indictment formally established the unit's identity and confirmed its attribution to FSB Center 16. Today's joint advisory is the most comprehensive public codification of the unit's methods to date.
SNMPv3, which closes the plaintext community-string vulnerability that Center 16 exploits, was standardized in 2002. The reason SNMPv1 and v2c remain deployed is not ignorance of the risk — it is operational inertia. Many network devices in critical infrastructure were configured a decade or more ago, and upgrading SNMP versions requires reconfiguring every management tool, monitoring system, and access control list that interacts with those devices. In large organizations with thousands of network devices, that is a significant undertaking that competes for engineering resources against other priorities. The advisory represents a formal government statement that the cost of not doing it now exceeds the cost of doing it — because FSB Center 16 is actively exploiting that inertia.
Yes. Because Center 16's primary method uses SNMP — a legitimate management protocol — to issue commands to a router that the router itself recognizes as valid, the activity can be indistinguishable from authorized network management unless administrators are specifically monitoring for unexpected SNMP sources, spoofed IP addresses, or outbound TFTP connections. Configuration file theft that does not modify the router leaves no artifact on the device after the fact. Organizations that have not audited their network devices for unauthorized configuration changes, unexpected accounts, or SNMP traffic from unrecognized sources should assume that absence of alerts does not mean absence of compromise.
The advisory explicitly notes that FSB Center 16's techniques overlap with those of China-linked threat actor Salt Typhoon, and that the recommended mitigations are effective against "similar TTPs used by other" threat actors. SNMPv3 upgrade, Smart Install disablement, firewall restrictions on SNMP and TFTP, and end-of-life device replacement reduce attack surface against the full class of router-targeting campaigns — including the APT28 FrostArmada campaign (disrupted April 2026), China's ORB network infrastructure campaigns, and commodity botnet operators that use default credential scanning at industrial scale.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
