Particle.news

Allied Agencies Attribute Global Router Campaign to Russia’s FSB Centre 16

The agencies say the group copies router configurations via weak SNMP credentials, exfiltrates them over TFTP or exploits Cisco Smart Install, posing risk to critical sectors worldwide.

Overview

  • On Monday, July 13, 2026, the NSA, FBI, CISA and international partners issued a joint advisory that publicly attributes an ongoing router-compromise campaign to Russia’s FSB Centre 16.
  • The advisory says operators scan for routers using default or weak SNMP community strings, issue commands from spoofed IPs to copy device configuration files, and move those files off networks using the Trivial File Transfer Protocol (TFTP).
  • Investigators also document use of legacy Cisco Smart Install flaws, including CVE-2018-0171, to gain persistent access to unpatched or end-of-life devices.
  • Agencies urge concrete defenses such as upgrading to SNMPv3, disabling Cisco Smart Install, enforcing strong unique passwords, blocking TFTP and SNMP at network edges, applying firmware updates, and replacing end-of-life hardware.
  • The advisory accompanies UK and EU public attribution and sanctions for late-2025 attacks on Poland’s energy grid and follows a recent law-enforcement disruption of a separate router campaign that included court-authorized FBI remediation to remove malicious DNS settings.