PI Global Investments
Infrastructure

State-Sponsored Russian Hackers Exploit Vulnerable Routers to Compromise Critical Infrastructure


Russian hackers are exploiting poorly configured routers to compromise critical infrastructure, a cybersecurity advisory by the FBI, CISA, and the security agencies of 15 U.S. allies warns.

The attacks, executed by Russia’s Federal Security Service (FSB) Center 16, target energy, communications, defense industrial base, healthcare, financial services, defense, and state and local government services.

The hacking campaign is attributed to the Russian hacking group tracked as Berserk Bear (CrowdStrike), Energetic Bear (CrowdStrike), Crouching Yeti (Kaspersky), Dragonfly (Symantec/Broadcom), Ghost Blizzard (Microsoft), and Static Tundra (Cisco).

How Russian hackers target critical infrastructure

According to the advisory, the attackers scan for weak Simple Network Management Protocol (SNMP) passwords to locate vulnerable routers to exploit. They also search for Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication by scanning IP ranges. Community strings typically contain shared or default passwords that some network defenders forget to update.

To avoid detection, the attackers execute their queries via proxies to mask the true origin of their requests. They send SNMP Set-Requests from spoofed IP addresses containing Object Identifiers, copy configuration files “config.bkp” or “output.txt,” and transfer them via Trivial File Transfer Protocol to attacker-controlled VPS servers.

“Router infrastructure is one of the most consistently overlooked parts of an attack surface, and adversaries like FSB-linked actors know this,” said Seemant Sehgal, Founder & CEO, BreachLock. “When you can pull a device config file over SNMP using the string ‘public’, you have a map of the internal network handed to you before you’ve done anything sophisticated.”

The attackers also exploit known security vulnerabilities in Cisco’s Smart Install feature and web management portals, including CVE-2018-0171 and CVE-2008-412813. Other threat actors, such as state-sponsored Chinese hackers Salt Typhoon, have employed similar tactics to compromise Western critical infrastructure.

“The techniques in this advisory are not new; however, the breadth of international attribution should remove any doubt that this remains an active and coordinated threat to critical infrastructure,” said Matthew Hartman, Chief Strategy Officer at Merlin Group. “Organizations should treat internet-facing network infrastructure as a priority attack surface by eliminating default credentials, restricting management interfaces, and ensuring that routers receive the same level of monitoring and patching as other critical systems.”

Securing critical infrastructure from Russian attacks

The authoring agencies recommended hardening routers, including replacing default passwords with unique and strong passwords, implementing SNMPv3 to replace SNMPv1 and SNMPv2, blocking TFTP, SMI, and SNMP protocols, updating firmware, and disabling the Cisco Smart Install feature for qualifying routers.

Where it is impossible to replace SNMP, network defenders should disable default community strings, and enforce read-only access after disabling read-write access. Other recommendations include using Cisco Type 8 password hashing, enabling multi-factor authentication, and monitoring local accounts to identify and terminate unauthorized instances.

Since Russian hackers use SNMP OIDs, network defenders should also restrict the functionality via the Management Information Base (MIB). They should also restrict management protocols using control lists to prevent requests from rogue IP addresses typically used by Russian hackers to compromise critical infrastructure.

Similarly, replacing end-of-life devices with new hardware and keeping their software updated should reduce the attack surface. Attackers continue to exploit software vulnerabilities dating back to the late 2000s, such as CVE-2008-412813, because many organizations have failed to apply the necessary security patches.

Critical infrastructure organizations should also take advantage of the free cybersecurity programs offered by CISA and the NSA.

The agencies also published a list of indicators of compromise to help network defenders in threat hunting to protect critical infrastructure organizations.

“The most important takeaway from this campaign is that sophisticated adversaries continue to exploit relatively basic weaknesses because they know those weaknesses still exist,” said Louis Eichenbaum, Federal CTO at ColorTokens. “This is especially true with our OT systems that manage our critical infrastructure as they often use legacy components. Default credentials, exposed management interfaces, and flat networks remain common across critical infrastructure. Organizations should assume that perimeter devices will eventually be compromised and focus on building resilience through visibility, least privilege, and microsegmentation.”

A history of targeting Western critical infrastructure

Since 2011, the state-sponsored hacking group has targeted critical infrastructure to advance Russian strategic geopolitical objectives.

In 2017 and 2018, the FBI and the Department of Homeland Security warned of Dragonfly targeting the energy sector by compromising trusted third-party suppliers to gain initial access and move laterally across the intended target’s network.

The Russian hacking group was also attributed to cyber attacks on Polish critical infrastructure, including renewable energy.

In 2025, Cisco warned of Static Tundra exploiting a 7-year-old security vulnerability, CVE-2018-0171, to collect device configuration files.

 



Source link

Related posts

Inside Orbital’s ambitious plan to move AI infrastructure into space to solve power and cooling issues

D.William

Tokenisation in the GCC: Infrastructure Modernisation and Financial Risk

D.William

Business News: Stock and Share Market News, Economy and Finance News, Sensex, Nifty, Global Market, NSE, BSE Live IPO News

D.William

Leave a Comment