Full Report
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Analysis Summary
# Threat Actor: Centre 16 (FSB)
## Attribution & Identity
* **Identification:** Centre 16 of Russia’s Federal Security Service (FSB).
* **Known Aliases:** Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra.
* **Associations:** State-sponsored Russian intelligence; linked to proxy networks involving both state actors and cyber criminals.
## Activity Summary
Recent activities involve the global, opportunistic exploitation of inadequately configured routers and network devices. Notable operations include:
* **Poland Energy Grid Attack (December 2025):** Attributed by the UK and EU, this attack targeted Poland’s energy infrastructure with the potential to cause power outages for 500,000 civilians.
* **Global Router Exploitation:** Systematic scanning and compromising of network devices belonging to Critical National Infrastructure (CNI) organizations.
## Tactics, Techniques & Procedures
* **Internet Scanning:** Massive scanning for devices using default or weak Simple Network Management Protocol (SNMP) community strings.
* **Protocol Exploitation:** Exploiting legacy SNMP versions (v1 and v2c) and weak passwords.
* **Vulnerability Exploitation:** Leveraging well-known vulnerabilities in Cisco devices, specifically targeting the Cisco Smart Install (SMI) feature.
* **Web Portal Exploits:** Utilizing flaws in web management portals to gain unauthorized control over network devices.
* **Access Control Evasion:** Bypassing weak access controls on management protocols to achieve persistence and lateral movement.
## Targeting
* **Sectors:** Critical National Infrastructure (CNI), including Communications, Defence, Energy, Financial Services, Government, and Healthcare.
* **Geography:** Global targeting; specific mentions include Poland (energy sector) and the United Kingdom.
* **Victims:** Polish energy grid; various unnamed CNI organizations globally.
## Tools & Infrastructure
* **Malware/Tools:** SNMP scanners, Cisco Smart Install (SMI) exploitation tools.
* **Infrastructure:**
* **Protocols:** SNMP (Simple Network Management Protocol).
* **Hardware:** Cisco routers and other network appliances.
* **C2/Domains:** The advisory refers to the use of proxy networks and cybercriminal infrastructure to obfuscate state activity.
## Implications
Centre 16 represents a high-tier strategic threat to global stability. Their shift toward "opportunistic" exploitation of CNI suggests a strategy of pre-positioning for disruptive or destructive effects, as evidenced by the attempt to disable Poland's power grid. The actor's ability to blend state-directed intelligence goals with criminal proxy networks increases the complexity of attribution and defense.
## Mitigations
* **SNMP Hardening:** Disable legacy SNMP versions (v1 and v2c) and migrate to SNMPv3, which supports encryption and authentication.
* **Credential Hygiene:** Implement strong, unique, and complex passwords for all network management interfaces; change all default community strings.
* **Access Controls:** Restrict access to management protocols (SSH, SNMP, SMI) through Access Control Lists (ACLs) and ensure they are not exposed to the public internet.
* **Disable Unused Services:** Specifically disable the Cisco Smart Install (SMI) feature if not required for operations.
* **Framework Adoption:** Follow the NCSC Cyber Assessment Framework (CAF) and obtain Cyber Essentials certification to meet baseline security standards.