Centre 16 is a cyber operational division of Russia’s Federal Security Service (FSB) associated with state-backed intrusion, espionage, and disruptive activity against critical infrastructure and network edge devices. It has been publicly linked to Russian government cyber operations and is associated in reporting with aliases including Berserk Bear, Static Tundra, and Ghost Blizzard; reporting also ties subunits such as Turla and Star Blizzard to Centre 16. Centre 16 has been attributed to the December 2025 cyberattack against Poland’s power grid. That operation sought to disrupt communications between renewable energy hardware and power distribution operators and included an attempted deployment of the destructive wiper malware DynoWiper. The attack did not achieve widespread disruption, but it was assessed as a sabotage-oriented operation against energy infrastructure. The group has also been identified targeting vulnerable routers and other networking devices worldwide, including within critical national infrastructure. Its tradecraft includes reconnaissance and scanning for exposed or poorly configured devices, especially those using legacy SNMP configurations and default or weak community strings. It has abused SNMP access to obtain device configuration data, transfer that data to attacker-controlled infrastructure, and facilitate persistent access. Centre 16 activity has also included exploitation of Cisco device weaknesses, including Smart Install exposure and other known vulnerabilities, as well as exploitation of web portal flaws to seize network devices. Organizations assessed as particularly at risk from Centre 16 activity include entities in communications, energy, financial services, government, healthcare, and defense-related sectors. The actor’s behavior is consistent with Russian state objectives, combining cyber espionage access development with disruptive operations against strategically relevant targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian FSB cyber actors tied to disruptive sabotage and opportunistic exploitation of poorly configured and vulnerable networking devices worldwide, including critical infrastructure networks.
Attributed as the specific FSB division responsible for the December 2025 cyberattack targeting Poland's power grid, attempting to disrupt communications between renewable energy hardware and power distribution operators and deploy the destructive DynoWiper malware.
Russian FSB-linked threat actor opportunistically targeting vulnerable routers and critical national infrastructure worldwide, including organizations in communications, energy, healthcare, defense, and financial services.
Attributed as the operator behind the December 2025 cyberattack on Poland's power grid and described as targeting critical infrastructure sectors using SNMPv1/2 scanning, abuse of default or guessable community strings, configuration theft, and exploitation of Cisco devices including Smart Install.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.