Russian APTs Target Global Network Edge
International intelligence agencies warn that Russian state actors are actively exploiting network infrastructure and legacy devices.
A coalition of international government agencies has issued a warning regarding a coordinated effort by Russian state-sponsored advanced persistent threat (APT) actors to compromise global networking hardware. These campaigns focus on the systematic identification and exploitation of inadequately secured routers residing within critical infrastructure sectors.
Global Infrastructure Under Siege
The campaign involves a broad range of sectors including communication, energy, the defense industrial base, and healthcare. Intelligence services from the United States, Australia, Canada, the Czech Republic, Denmark, Estonia, Finland, Italy, New Zealand, Poland, Sweden, and the UK have identified multiple groups linked to the Russian Federal Security Service (FSB) Center 16 as the primary operators behind this activity.
These actors, including entities known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra, utilize automated scanning to pinpoint vulnerable devices at the network edge.
Tactics of Configuration Theft
The operational methodology employed by these groups frequently relies on the abuse of the Simple Network Management Protocol (SNMP). By transmitting specially crafted set-requests to targeted IP ranges, attackers instruct internal SNMP agents to copy device configurations. These files are subsequently exfiltrated using the Trivial File Transfer Protocol (TFTP) to controlled virtual private servers or compromised FTP nodes.
Many of these TTPs overlap with activity by other malicious cyber actors, such as Salt Typhoon.
The authoring agencies noted in their joint advisory.
Exploiting Legacy Vulnerabilities
Beyond protocol abuse, the attackers are actively leveraging long-standing vulnerabilities within network hardware. Documented activity includes the exploitation of flaws such as CVE-2008-4128 and CVE-2018-0171 to gain arbitrary command and code execution capabilities on Cisco systems. The prevalence of these older vulnerabilities underscores the risks inherent in maintaining legacy firmware.
- Agencies from 12 countries, including the US, UK, and Italy, contributed to the warning.
- At least 6 distinct threat groups linked to the Russian FSB are confirmed to be involved.
- Attackers are targeting 6 major critical infrastructure sectors, such as energy and finance.
Defensive Hardening Strategies
Agencies emphasize that network administrators must shift away from insecure legacy configurations to mitigate these threats. Recommendations include disabling Cisco Smart Install, retiring SNMPv1 and SNMPv2 in favor of SNMPv3 with modern encryption, and strictly restricting access to SNMP Object Identifiers (OIDs). The advisory also stresses the importance of isolating management protocols and ensuring that edge firewall ports deny unauthorized external communication.
The persistence of these actors in targeting foundational networking protocols suggests a strategic intent to maintain long-term access within sensitive environments. For organizations, the reliance on these techniques indicates that visibility into edge device logs and the rapid patching of known vulnerabilities are likely essential to disrupting these operations. Should these configurations remain unhardened, the risk of unauthorized configuration exfiltration and command execution remains elevated across the industry.
Sources
- SecurityWeek Original source
- joint advisory Also reporting
- CVE-2018-0171 Also reporting
- advisory Also reporting
Continue Reading
APT28's HOOKEDGE Backdoor Refines Espionage Tactics
New HOOKEDGE backdoor targets European governments, evolving from HEADLACE to evade defenses.
AI Defense Pledge Draws 130 Signatories
OpenAI-led open letter urges global cyber defense surge as AI-enabled attacks grow more capable.
PaperCut Zero-Day Patch Urged
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.