Particle.news
Download on the App Store

U.S. and Allies Say Russian FSB Unit Is Exploiting Weak Routers to Target Critical Infrastructure

A co-signed advisory warns stolen router configs and proxy networks give attackers a quiet route into power, health and government systems and urges immediate hygiene fixes.

Overview

  • The NSA, FBI, CISA and more than a dozen partner agencies published a joint advisory on Monday attributing active global router-targeting to the Russian FSB’s Center 16 and publishing technical indicators and mitigation steps.
  • The UK and EU simultaneously formalized attribution for a December 2025 attack on Poland’s energy grid and imposed sanctions on individuals and entities tied to the operations.
  • Agencies say the attackers scan for routers using legacy SNMP v1/v2 with default or weak community strings, then send SNMP set-requests to command devices to copy configuration files and exfiltrate them, usually over TFTP to actor-controlled servers.
  • Defenders are urged to take simple, immediate steps: move to SNMPv3 with modern encryption, disable Cisco Smart Install, block TFTP and SNMP at edge firewalls, apply firmware patches and replace end-of-life devices.
  • The campaign threatens sectors such as energy, communications, healthcare, finance and government because stolen router configs can contain admin credentials, map networks, enable DNS hijacking and turn devices into proxy infrastructure for further intrusion.