FSB Center 16 is a Russian Federal Security Service signals-intelligence cyber unit associated in public reporting with activity clusters and aliases including Static Tundra, Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, and Ghost Blizzard. The unit has conducted a long-running campaign, spanning more than a decade, focused on compromising internet-facing networking infrastructure—especially poorly configured or vulnerable routers and switches—to support espionage against critical infrastructure and government-related targets worldwide. The group is known for opportunistic mass scanning of exposed network devices, particularly those using legacy or weakly secured management services. A core tradecraft pattern involves identifying devices that accept default or weak SNMP community strings, abusing SNMP Set-Requests to trigger configuration export, and exfiltrating stolen device configurations. The unit has also exploited Cisco Smart Install and has at times leveraged Cisco device vulnerabilities including CVE-2018-0171 and CVE-2008-4128. Secondary attention has been given to web-based management interfaces on edge devices. Its collection objective centers on obtaining network-device configuration data that can reveal topology, credentials, access-control policies, routing relationships, and remote-access settings. Reporting also indicates interest in industrial-control-related protocols and applications within compromised environments, underscoring the strategic value of router and switch access for downstream reconnaissance and potential pivoting toward operational technology networks. In some cases, Center 16 has modified device configurations to maintain persistent unauthorized access, including changes to authentication settings and local privileged accounts. Public reporting has also linked related activity to modified network-device system images and bootloader-level persistence mechanisms. Priority victim sectors include communications, defense industrial base, energy, financial services, government services and facilities, and healthcare and public health. U.S. government reporting has also linked officers associated with Center 16, also identified as Military Unit 71330, to cyberattacks against U.S. government agencies, energy firms, and other critical infrastructure entities. The actor’s dominant motivation is espionage in support of Russian state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The actors also exploit Cisco Smart Install where it remains enabled, and occasionally weaponise known defects including CVE-2018-0171 and the end-of-life-only CVE-2008-4128.
The actors also exploit Cisco Smart Install where it remains enabled, and occasionally weaponise known defects including CVE-2018-0171 and the end-of-life-only CVE-2008-4128.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Long-running Russian cyber activity focused on exploiting vulnerable routers and edge devices via SNMP and Cisco Smart Install to collect configurations and exfiltrate them to attacker-controlled infrastructure.
Long-running Russian state-linked cyber operations compromising routers and other network devices in critical infrastructure, using SNMP abuse and Cisco Smart Install exploitation to steal and modify device configurations, maintain persistence, and enable follow-on access into ICS/OT environments.
Russian FSB signals-intelligence unit conducting router compromises to spy on critical infrastructure.
FSB Center 16 is accused of orchestrating cyberattacks against U.S. critical infrastructure, including government agencies and energy firms, and exploiting vulnerabilities in Cisco devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.