A joint advisory from cybersecurity agencies in 12 countries warned that Russian state hackers linked to FSB Center 16 are actively targeting vulnerable routers worldwide, focusing on devices exposed with default or weak SNMP credentials and community strings. The agencies said the actors can abuse SNMP to copy router configurations through OIDs and exfiltrate them over TFTP, while also exploiting older network-device flaws such as CVE-2018-0171 on Cisco equipment. High-risk sectors identified in the warning include communications, defence, energy, financial services, government, and healthcare, and the activity follows formal UK and EU attribution of cyber-attacks on Poland’s energy infrastructure to the same Russian service.
Separate reporting highlighted how compromised SOHO and home-office routers can be used for DNS hijacking that bypasses endpoint security and enables credential theft against remote workers. The attack path described combines documented Russian tradecraft, including APT28-linked router compromises, with downstream abuse such as redirecting traffic, harvesting NTLMv2 hashes, and stealing Microsoft 365 credentials and tokens. Defenders were urged to harden or replace poorly secured routers, move to SNMPv3, disable unnecessary exposed services, monitor for unauthorized DNS resolver changes and NXDOMAIN spikes, and factory-reset suspected devices before rotating affected credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
The UK NCSC issued a July 2026 advisory titled "UK and Allies urge critical sectors to improve defences against Russian intelligence targeting." It urged critical sectors to strengthen defenses against Russian targeting of poorly configured routers.
The UK and EU formally attributed coordinated late-2025 cyber-attacks on Poland’s energy infrastructure to Russian FSB Center 16. The UK said the attack failed but could have caused 500,000 citizens to lose electricity during winter.
Cisco warned in 2025 that FSB Center 16, also tracked as Static Tundra, was exploiting CVE-2018-0171 in unpatched Cisco devices using Smart Install. Cisco urged customers to patch or disable Smart Install where patching was not possible.
CISA added CVE-2023-23397, a critical Microsoft Outlook vulnerability, to its Known Exploited Vulnerabilities catalog. The reference notes APT28 has been documented exploiting this flaw.
DHS, the FBI, and the UK NCSC issued a joint alert describing a worldwide campaign by Russian state-sponsored actors targeting routers, switches, firewalls, and NIDS devices. The alert said the actors abused weak or legacy protocols including SNMP, Telnet, and Cisco Smart Install to steal configurations, harvest credentials, create GRE tunnels, and conduct man-in-the-middle operations.
Cisco first issued a patch for CVE-2018-0171, a vulnerability affecting devices using the Smart Install feature. Later reporting noted the flaw continued to affect unpatched and often end-of-life Cisco devices.
The FBI conducted operations to neutralize botnets based on Ubiquiti EdgeRouter devices used by APT28. The reference cites this as documented activity relevant to SOHO-router compromise tradecraft.
Cybersecurity agencies from 12 countries issued a joint advisory warning that Russian FSB Center 16 was actively targeting vulnerable routers worldwide. The advisory said the actors scan for routers using default or weak SNMP passwords and community strings and can steal configurations for exfiltration over TFTP.
The UK sanctioned individuals behind Lumma Stealer, saying Russia had used credentials stolen by the malware to support cyber espionage operations globally. The article also cites the UK National Crime Agency as reporting at least 2,100 Lumma victims in the UK within the previous six months.
Alongside the attribution of the Poland energy attacks, the EU and UK announced a joint sanctions package targeting 24 individuals and entities linked to destructive cyber and hybrid operations. The package also included action against cybercriminals involved in proxy networks tied to Russian intelligence services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourceeclypsium.com
Open sourceinfosecurity-magazine.com
Open sourcensa.gov
Open sourceus-cert.cisa.gov
Open sourcecisa.gov
Open sourcetools.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.