Introduction
Russian FSB attacks critical infrastructure by exploiting weak routers, legacy SNMP settings, and old Cisco Smart Install exposure. UK, US, and allied agencies have warned that Russia’s Federal Security Service Centre 16 continues to target poorly configured networking devices tied to critical infrastructure networks.
The threat actor is also tracked as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. Its activity focuses on router configuration theft, network mapping, and long-term intelligence collection against high-value sectors.
This campaign matters because the entry point is often a basic configuration failure. FSB Centre 16 does not need a sophisticated zero-day when routers still expose SNMPv1, SNMPv2, weak community strings, Cisco Smart Install, or end-of-life firmware.
The risk is serious for communications, defense, energy, financial services, government, and healthcare organizations. These sectors depend on stable network infrastructure, and router compromise gives attackers a map of how those networks operate.
This article explains how Russian FSB attacks critical infrastructure, why weak router hygiene creates national-level risk, and what security teams should fix immediately.
For related infrastructure defense context, see Digital Warfare’s vulnerability assessment services
Why Russian FSB Attacks Critical Infrastructure Now
Russian FSB attacks critical infrastructure because routers provide a valuable path into sensitive networks. A compromised router can reveal network topology, routing rules, VPN settings, access control lists, internal IP ranges, and sometimes stored credentials.
That information gives intelligence operators a powerful advantage. They can study the environment before attempting deeper access. They can also identify which internal systems may support operational technology, industrial control, healthcare delivery, government services, or financial operations.
The advisory carries unusual weight because it comes from a broad coalition of allied cyber agencies. This level of coordination signals that governments see the activity as persistent, global, and serious.
However, the recommended fixes are practical. Organizations can reduce much of the risk by hardening routers, disabling legacy features, replacing weak credentials, blocking unnecessary protocols, and patching known vulnerabilities.
What Allied Agencies Warned About
The joint warning focuses on router hygiene. It urges organizations to secure networking devices before Russian state-sponsored actors can use them as entry points.
FSB Centre 16 has targeted networking devices for more than a decade. The FBI previously warned that the group exploited SNMP and end-of-life devices running Cisco Smart Install CVE-2018-0171. The group also collected configuration files for thousands of networking devices associated with US entities across critical infrastructure sectors.
This is not only a future risk. It is an active and historically documented campaign.
The advisory also overlaps with a broader pattern of nation-state router targeting. China-linked Salt Typhoon and Russia-linked APT28 have also targeted edge and router infrastructure in separate campaigns.
Therefore, fixing router hygiene does not only defend against one Russian unit. It reduces exposure to a full class of nation-state network device attacks.
How Russian FSB Attacks Critical Infrastructure Through Routers

Russian FSB attacks critical infrastructure by targeting the routers and network devices that sit at the edge of sensitive environments.
The attack usually starts with scanning. The actors look for internet-facing routers that expose SNMP and accept default or weak community strings.
Once they find a vulnerable device, they use SNMP commands to copy the device configuration. They can then exfiltrate that file using TFTP or another weak transfer path.
In some cases, FSB Centre 16 also exploits Cisco Smart Install and related Cisco IOS or IOS XE weaknesses. These paths can give attackers direct control over devices or access to sensitive configuration data.
The stolen configuration data then supports reconnaissance, credential discovery, and follow-on targeting.
Stage One: Scanning for Weak SNMP Routers
The first stage targets Simple Network Management Protocol.
SNMP helps administrators monitor and manage network devices. Older versions, especially SNMPv1 and SNMPv2, rely on community strings as shared passwords.
Many routers still use default strings such as public or private. Attackers know this and scan for devices that accept them.
This stage is simple but effective. A router that exposes weak SNMP can give attackers access to sensitive management functions without needing malware on the device.
Organizations should treat exposed SNMPv1 and SNMPv2 as urgent findings, especially in critical infrastructure environments.
Stage Two: Stealing Router Configuration Files
After finding a weak SNMP device, the attackers try to copy its configuration file.
That file can contain routing information, interface details, internal network ranges, access control lists, VPN settings, and other operational details.
For attackers, this is a network map. It tells them how the environment is built and where they may be able to move next.
In some cases, router configurations may also expose credentials or weak secrets. Even when credentials are not present, topology data alone gives the attacker a major intelligence advantage.
This is why configuration file theft should be treated as a serious incident, not a low-level network event.
Stage Three: Exfiltrating Data Through TFTP
TFTP is an old file transfer protocol that lacks strong authentication. Attackers use it because many environments do not monitor it closely.
Once the router copies the configuration file, the attacker can instruct the device to transfer the file to actor-controlled infrastructure.
This traffic may leave the network without triggering alerts if outbound TFTP is allowed.
Security teams should block TFTP at the perimeter unless a documented business need exists. They should also monitor for any network device attempting outbound TFTP transfers.
A router should not quietly send its configuration file to an external host.
Stage Four: Abusing Cisco Smart Install
Cisco Smart Install was designed to simplify switch deployment. However, when exposed or left enabled in unsafe environments, it creates serious risk.
The FBI has tied FSB Centre 16 activity to exploitation of Cisco Smart Install CVE-2018-0171. This vulnerability affects Cisco IOS and IOS XE devices and can allow unauthenticated remote abuse under certain conditions.
A device that still exposes this feature gives attackers a known path to configuration theft or device control.
Organizations should disable Cisco Smart Install wherever it is not required. They should also patch affected Cisco IOS and IOS XE devices and verify that exposed services are no longer reachable.
Stage Five: Mapping Critical Infrastructure Networks
Once attackers steal router configurations, they can map the network more accurately.
This helps them identify important segments, management paths, VPN links, and possible routes toward operational systems.
For critical infrastructure operators, this is especially dangerous. Routers often connect business networks, operational technology, vendor access paths, and remote management infrastructure.
If attackers understand those relationships, they can plan more precise intrusions.
Therefore, organizations should treat router configuration exposure as a potential precursor to deeper compromise.
Russian FSB Attacks Critical Infrastructure Across Key Sectors
Russian FSB attacks critical infrastructure across sectors that support national resilience.
The highest-risk sectors include communications, defense, energy, financial services, government, and healthcare. These environments rely heavily on stable network connectivity and trusted infrastructure.
A compromised router in one of these sectors can create broad downstream risk. It may expose service dependencies, security zones, vendor links, or management networks.
This is why router hygiene is more than a network administration issue. It directly affects national security, business continuity, and public safety.
Energy Sector Risk
Energy organizations should treat this advisory with urgency.
Routers and network devices often support remote access, grid management, monitoring, vendor connectivity, and industrial control environments.
If attackers steal configurations, they may learn how corporate networks connect to operational systems. That knowledge can support future disruption attempts.
The reported attack activity around Poland’s energy sector shows why this matters. Even when an attack does not cause a blackout, it can disrupt operations, communications, and trust in energy resilience.
Healthcare Sector Risk
Healthcare networks depend on availability.
Hospitals, clinics, laboratories, and medical support providers rely on networked systems for care delivery, imaging, records, devices, and communications.
A compromised router can expose internal network structure and support follow-on intrusion. In healthcare, that can affect patient safety as well as data security.
Healthcare organizations should review internet-facing routers, remote access paths, SNMP exposure, and end-of-life devices immediately.
Government and Defense Risk
Government and defense organizations face direct intelligence collection risk.
Router configuration theft can expose sensitive internal architecture, VPNs, restricted networks, trusted partner links, and security zones.
For defense industrial base organizations, this can help attackers understand where sensitive programs, contracts, and systems may reside.
Government and defense teams should combine router hygiene with privileged access review, network segmentation, and stronger external attack surface monitoring.
For related service support, see Digital Warfare’s penetration testing services
Timeline of Russian FSB Router Targeting
FSB Centre 16 has targeted networking devices for more than a decade.
Since at least the mid-2010s, the group has shown interest in routers and legacy network infrastructure. The FBI has connected the unit to long-running compromise of devices accepting legacy protocols such as SNMPv1, SNMPv2, and Cisco Smart Install.
In August 2025, the FBI warned that Russian FSB cyber actors were targeting networking devices and critical infrastructure.
In July 2026, NSA and partners released updated router hygiene guidance to help defenders reduce exposure to Russian state-sponsored targeting.
This timeline shows that router targeting is not temporary. It is a persistent intelligence collection method that continues because weak configurations remain widespread.
Related APT28 Router Campaigns
FSB Centre 16 is not the only Russian intelligence-linked actor targeting routers.
The UK NCSC has also documented APT28 router exploitation used to enable DNS hijacking. APT28 is associated with Russia’s GRU, not FSB Centre 16.
That distinction matters. These are separate Russian intelligence-linked activities, but they reinforce the same defensive lesson.
Routers are now a major battleground. Attackers use them for configuration theft, DNS manipulation, credential interception, and infrastructure staging.
Defenders should harden network devices as mission-critical assets.
Enterprise Impact of Russian FSB Attacks Critical Infrastructure
Russian FSB attacks critical infrastructure create long-term exposure because stolen router configurations remain useful even after the initial theft.
A configuration file can reveal how a network looked at the time of compromise. If the organization does not change architecture, access controls, credentials, or management paths, that intelligence may remain valuable for years.
This means remediation must go beyond closing one exposed port.
Organizations should review whether stolen configurations could expose VPNs, internal routes, management addresses, device credentials, or operational technology pathways.
Where risk is high, teams should rotate secrets, update access controls, and consider network design changes.
Why Stolen Network Maps Create Long-Term Risk
A stolen router configuration is not just a file. It is a blueprint.
It can show attackers where internal systems live, how branches connect, which networks are trusted, and how management traffic flows.
Even if the attacker does not use the information immediately, they can store it for future operations.
That is why critical infrastructure operators should treat configuration theft as an intelligence loss. The response should include architecture review, credential rotation, access control validation, and monitoring changes.
Real-World Attack Scenarios
In an unmonitored SNMP router scenario, an energy utility exposes SNMPv2 with a weak community string. FSB Centre 16 scans the device, issues SNMP commands, copies the configuration file, and transfers it to external infrastructure. The utility sees no endpoint alert because the activity happens on the router.
In an unpatched Cisco Smart Install scenario, a government agency still runs vulnerable Cisco IOS devices. Attackers exploit CVE-2018-0171, extract configuration data, and use embedded network details to plan internal access.
In a critical infrastructure mapping scenario, attackers collect router configurations over time. They use the data to understand which systems connect to operational technology, vendor networks, and remote access paths.
These scenarios reflect the attack mechanics described in public advisories. They do not assume unverified compromise beyond the documented campaign patterns.
How to Defend Against Russian FSB Attacks Critical Infrastructure

Defending against Russian FSB attacks critical infrastructure starts with router hygiene.
Security teams should upgrade to SNMPv3, disable legacy SNMP versions, remove default community strings, and block unnecessary management protocols.
They should also disable Cisco Smart Install, patch Cisco IOS and IOS XE devices, retire end-of-life hardware, and move management traffic to restricted networks.
These controls do not require a new security platform. They require disciplined configuration management and verification.
Upgrade to SNMPv3 Immediately
SNMPv1 and SNMPv2 should not remain active on production network devices.
Organizations should move to SNMPv3 with authentication and privacy protections enabled. Where possible, use the strongest encryption and authentication options the device supports.
If legacy SNMP must remain temporarily, remove default community strings immediately. Also disable read-write access unless a documented business requirement exists.
Management access should come only from trusted hosts on dedicated networks.
Disable Cisco Smart Install
Cisco Smart Install should be disabled on all devices unless there is a documented and current operational need.
Organizations should verify the setting directly rather than assume it is disabled. On Cisco devices, teams can use device-specific commands such as show vstack config where applicable.
If Smart Install is enabled, disable it and confirm that the device no longer exposes the service.
Teams should also patch Cisco IOS and IOS XE devices for CVE-2018-0171 and related flaws.
Block TFTP at the Network Perimeter
Outbound TFTP should be blocked unless the organization has a strict business need.
Routers and switches should not send configuration files to external hosts. Any such attempt should trigger investigation.
Security teams should review firewall rules, router ACLs, and monitoring policies to ensure TFTP cannot be used for silent configuration exfiltration.
They should also monitor for unusual file transfer behavior from network devices.
Replace Weak Community Strings and Passwords
Default SNMP community strings are a primary attack enabler.
Security teams should audit every router, switch, firewall, and network appliance for default or common values.
Replace weak strings with strong, unique values. Then confirm that read-write access is disabled unless required.
The same review should include device administrator passwords, local accounts, backup accounts, and legacy credentials.
Retire End-of-Life Network Devices
End-of-life devices create permanent exposure.
If a router or switch no longer receives security updates, attackers can continue targeting it with known flaws.
Organizations should inventory all network devices and identify unsupported hardware. Then they should create replacement timelines based on exposure, criticality, and exploitability.
Critical infrastructure operators should prioritize internet-facing and remote management devices first.
Move Management Traffic Out of Band
Management traffic should not travel across broad production networks.
Organizations should move SNMP, SSH, web administration, and device management access to dedicated out-of-band management networks.
Access control lists should restrict which hosts can issue management commands. Logging should capture every administrative session.
This reduces exposure and makes anomalous management traffic easier to detect.
Monitor for Router Configuration Theft
Security teams should monitor for signs of router configuration theft.
Useful signals include unexpected SNMP Set-Requests, outbound TFTP, new configuration files such as config.bkp or output.txt, unusual administrator logins, and changes to device startup or running configurations.
Teams should also review logs from network devices, firewalls, VPN concentrators, and management servers.
If configuration theft is suspected, rotate exposed secrets and review network design assumptions.
For broader exposure discovery, see Digital Warfare’s attack surface management services
Security Lessons From Russian FSB Attacks Critical Infrastructure
Russian FSB attacks critical infrastructure show that basic configuration failures can become national security risks.
A weak SNMP string may look like a small issue. However, when it exposes a router configuration, it can give a state actor the map it needs for future operations.
The campaign also shows that attackers prefer reliable paths. They keep using old techniques because organizations keep leaving old weaknesses exposed.
Finally, the advisory shows that router hygiene defends against more than one actor. The same controls reduce risk from Russian FSB actors, GRU-linked activity, China-linked router campaigns, criminal groups, and opportunistic scanners.
Why Configuration Hygiene Is National Security
Configuration hygiene is not only an IT housekeeping task.
Routers sit between business systems, operational technology, cloud services, vendors, users, and remote access paths.
If attackers control or understand those routers, they gain strategic visibility.
For critical infrastructure, that visibility can affect public safety, service continuity, and national resilience.
Why Router Security Needs Executive Attention
Router security often receives less attention than endpoints, cloud systems, or identity platforms.
That needs to change. Routers carry the traffic, enforce boundaries, and reveal how networks are built.
Executive teams should ask whether the organization knows which routers are internet-facing, which protocols are exposed, which devices are end-of-life, and whether configuration files are protected.
If those answers are unclear, the organization has a governance problem as well as a technical one.
Key Takeaway on Russian FSB Attacks Critical Infrastructure
Russian FSB attacks critical infrastructure by exploiting weak router hygiene.
FSB Centre 16 has targeted networking devices for more than a decade. The group uses legacy SNMP, weak community strings, Cisco Smart Install exposure, and configuration theft to map sensitive networks.
The defense is practical. Upgrade to SNMPv3, disable SNMPv1 and SNMPv2, disable Cisco Smart Install, patch CVE-2018-0171, block TFTP, replace weak credentials, retire unsupported devices, and isolate management traffic.
Organizations in communications, defense, energy, financial services, government, and healthcare should treat this advisory as urgent.
What Organizations Should Do Now
Start by identifying every internet-facing router, switch, firewall, and network appliance.
Next, disable SNMPv1 and SNMPv2 wherever possible. Move required monitoring to SNMPv3 with strong authentication and encryption.
Then disable Cisco Smart Install and patch Cisco IOS and IOS XE devices for CVE-2018-0171.
Block outbound TFTP traffic at the perimeter and monitor any network device attempting external file transfers.
Replace default SNMP community strings, weak passwords, and old local administrator credentials.
Retire end-of-life devices that cannot receive security updates.
Finally, review whether router configuration files could expose internal routes, VPNs, credentials, or operational technology paths. If exposure is possible, rotate secrets and update network access controls.
For the one external source in this article, review CISA’s Russian cyber threat guidance: Russia Threat Overview and Advisories
Frequently Asked Questions About Russian FSB Attacks Critical Infrastructure
What Are Russian FSB Attacks Critical Infrastructure?
Russian FSB attacks critical infrastructure are campaigns attributed to Russia’s Federal Security Service Centre 16 that target networking devices, especially routers, to steal configurations and map sensitive networks.
Who Is FSB Centre 16?
FSB Centre 16 is a Russian Federal Security Service unit associated with long-running cyber espionage. It is also tracked by names including Berserk Bear, Energetic Bear, Dragonfly, Ghost Blizzard, Static Tundra, and Crouching Yeti.
How Do Russian FSB Attacks Critical Infrastructure Work?
The attacks often start with scanning for routers that expose SNMPv1 or SNMPv2 with weak community strings. The actors then copy router configuration files and exfiltrate them, often using weak protocols such as TFTP.
Why Are Router Configuration Files Valuable?
Router configuration files can reveal internal IP ranges, routing rules, VPN settings, access control lists, management paths, and sometimes credentials. This gives attackers a map of the target network.
What Is Cisco Smart Install CVE-2018-0171?
CVE-2018-0171 is a critical Cisco IOS and IOS XE vulnerability tied to the Cisco Smart Install feature. FSB Centre 16 has exploited it as part of router-targeting activity.
Which Sectors Face the Highest Risk?
Communications, defense, energy, financial services, government, and healthcare face the highest risk because these sectors operate critical networks that state actors actively target.
How Should Organizations Defend Against These Attacks?
Organizations should upgrade to SNMPv3, disable SNMPv1 and SNMPv2, disable Cisco Smart Install, patch Cisco IOS and IOS XE devices, block TFTP, replace weak credentials, retire end-of-life devices, and isolate management traffic.
Does This Threat Only Apply to Russia?
No. The same router hygiene controls also reduce exposure to other nation-state and criminal campaigns, including router-targeting activity associated with China-linked and GRU-linked actors.

