Protect your router against Russian state-sponsored targeting
From NCSC Improve router hygiene to protect against Russian state- targeting
Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint advisory provides additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat.
The authoring and co-sealing agencies strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government- exploitation of vulnerable routers.
United States National Security Agency (NSA) United States Cybersecurity and Infrastructure Security Agency (CISA) United States Federal Bureau of Investigation (FBI) United States Department of Defense Cyber Crime Center (DC3) Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) New Zealand National Cyber Security Centre (NCSC-NZ) United Kingdom National Cyber Security Centre (NCSC-UK) Czech Republic National Cyber and Information Security Agency (NÚKIB) Danish Defence Intelligence Service (DDIS) Estonian Foreign Intelligence Service (EFIS) Estonian Information System Authority (RIA) Finnish Defence Intelligence (FDI) Finnish Security and Intelligence Service (SUPO) French National Cybersecurity Agency (ANSSI) Italian External Intelligence and Security Agency (AISE) Italian Internal Intelligence and Security Agency (AISI) The Military Counterintelligence Service of Poland (SKW) Sweden National Cyber Security Centre (NCSC-SE)
The Russian FSB Center 16 cyber actors primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation. The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication. These scans, run via proxies, consist of SNMP Set-Requests from a spoofed IP address containing Object Identifiers (OIDs) that instruct the SNMP agent on poorly configured networking devices to :
Copy its configuration to a file, often called “config.bkp” or “output.txt”.
Transfer the file, typically using Trivial File Transfer Protocol (TFTP), to an actor-controlled leased virtual private server (VPS) or compromised FTP server.
While SNMP scanning is the primary method the actors use to discover and exploit poorly configured networking devices, they occasionally exploit common vulnerabilities and exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices. The actors previously exploited at least the following CVEs :
Many of these TTPs overlap with activity by other malicious cyber actors, such as Salt Typhoon External Link . Even though this CSA focuses on Russian FSB Center 16 cyber activity, the mitigations below should detect and counter these and similar TTPs used by other actors.
The authoring agencies highly recommend network defenders implement the following mitigations to harden networks against this exploitation:
Disable Cisco Smart Install on all devices. Use SNMPv3 with “authPriv” configured to the most modern encryption standard that is supported by the device instead of SNMPv1 or SNMPv2. Use strong, unique passwords for local accounts on network devices and configure credentials to be stored securely to prevent reuse of compromised passwords. Monitor and restrict access to SNMP OIDs using a Management Information Base (MIB) allow list. Reference the vendor-specific MIB for the network devices and monitor OIDs for indications of reconnaissance or misconfiguration in logs or intrusion detection systems (IDS). IDS rules should be written for inbound SNMP Set-Requests that contain OIDs targeting sensitive device data. Restrict management protocols. Update network device software and firmware images, especially to patch known vulnerabilities, and upgrade end-of-life devices to supported ones.
From the USA-equivalent advisory:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
