A Global Sweep for Weak Routers
Twelve countries just dropped a coordinated warning about Russian state hackers. Their target? Your router. Specifically, any router still using default or weak Simple Network Management Protocol (SNMP) passwords and community strings.
The joint advisory, released this week, points the finger squarely at the Russian Federal Security Service (FSB) Center 16. This unit is known by many names — Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. Different aliases, same mission: scanning the internet for vulnerable network devices.
And they’re not just looking. They’re actively exploiting what they find.
Who’s at Risk? Pretty Much Everyone Critical
Communications, defense, energy, financial services, government, and healthcare. That’s the list of sectors the advisory flags as most exposed. If you work in any of these fields, this advisory is addressed to you — not as a formality, but as a genuine call to action.
The threat isn’t hypothetical. In late 2025, a coordinated cyber-attack hit Poland’s energy grid. On July 13, the UK and EU officially attributed it to FSB Center 16. The UK government’s statement was blunt: the attack failed, but it could have cut electricity to 500,000 citizens in the middle of winter.
That’s the scale we’re talking about.
Why SNMP Is the Achilles’ Heel
Here’s the technical crux. SNMPv1 and SNMPv2 transmit community strings in plaintext. That means anyone sniffing network traffic can grab them. Once an attacker has a valid community string, they can use Object Identifiers (OIDs) to command the router to copy its configuration and send it off via Trivial File Transfer Protocol (TFTP).
Those stolen configuration files then end up on a virtual private server leased by the threat actor or a compromised FTP server. Game over for network security.
The fix? SNMPv3. It comes with built-in authentication and encryption, protecting management traffic from interception and tampering. The advisory is unambiguous: switch to SNMPv3 now.
Also Patch Your Cisco Devices
Scanning for weak SNMP credentials isn’t the only trick in Center 16’s playbook. They’ve also been known to exploit CVEs in Cisco devices. In 2025, Cisco warned about CVE-2018-0171, a seven-year-old vulnerability in the Smart Install feature. It affects unpatched, often end-of-life Cisco devices — and Center 16 has been actively exploiting it.
The patch has existed since 2018. If you haven’t applied it, you’re leaving a door wide open. If patching isn’t possible, disable Smart Install entirely. There’s no excuse for running unpatched network gear in 2025.
Same Tactics, Different Groups
Interesting note from the advisory: many of the tactics, techniques, and procedures (TTPs) used by Center 16 overlap with other threat actors, including China-linked group Salt Typhoon. That’s a reminder that attribution in cyberspace is messy. But the operational overlap also means that defending against one group often helps against another.
The advisory was co-authored by agencies from Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, Sweden, the UK, and the US. That’s a broad coalition — and it signals how seriously these nations take this specific threat.
Sanctions and the Lumma Stealer Connection
Alongside the advisory, the EU and UK issued a joint sanctions package targeting 24 individuals and entities behind the destructive cyber and hybrid operations. That includes cybercriminals running proxy networks linked to Russian intelligence services.
The UK is also sanctioning individuals behind Lumma Stealer, an info-stealing malware. The UK government says Russia has used stolen credentials from Lumma Stealer to conduct cyber espionage globally, supporting Kremlin objectives.
Here’s a number that should grab your attention: the National Crime Agency reports at least 2,100 Lumma Stealer victims in the UK in just the last six months. That’s not a niche problem — that’s a widespread campaign.
What You Should Do Right Now
Don’t wait for your organization to be the next headline. Here’s a practical checklist based on the advisory:
- Upgrade to SNMPv3 — disable SNMPv1 and v2 entirely if possible.
- Audit your router configurations — change any default or weak community strings immediately.
- Patch CVE-2018-0171 on all Cisco devices, or disable Smart Install.
- Monitor for unauthorized TFTP traffic — this is a common exfiltration method.
- Segment your network to limit lateral movement if a device is compromised.
Router security has never been glamorous. But it’s the frontline of network defense, and Russian state hackers know it. The advisory makes one thing clear: they’re actively scanning for weaknesses right now.
Make sure you’re not an easy target.