Threat Intelligence
US and Allies Warn of Russian Critical Infrastructure Attacks
A joint advisory from 19 allied cybersecurity agencies published on 13 July 2026 warns that Russian state hackers are systematically compromising routers to gain access to critical infrastructure networks worldwide. I am breaking down what the advisory says, how the attacks work, and what defenders need to do.
What the Advisory Says
The US National Security Agency (NSA), FBI, and Cybersecurity and Infrastructure Security Agency (CISA) co-authored the advisory alongside 15 other agencies from Australia, the UK’s NCSC, Canada, New Zealand, Estonia, Finland, France, and Italy. The NCSC also published its own aligned advisory, co-sealed with agencies from Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, Sweden, and the United States.
The attribution is to Russian Federal Security Service (FSB) Centre 16. This group is tracked under multiple names including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. They have been active for years, but these advisory details a specific operational methodology targeting critical infrastructure.
The Attack Methodology
The attackers scan internet-connected IP address ranges for routers accepting default or common SNMP authentication strings. Once they find a vulnerable device, they issue commands using spoofed IP addresses to copy device configuration files and exfiltrate them via TFTP to actor-controlled servers.
The technique is not new but remains effective because organizations continue to deploy routers with default or weak SNMP configurations. In August 2025, the FBI warned that the same group had been targeting critical infrastructure using CVE-2018-0171, a Cisco Smart Install vulnerability, since November 2021.
Sectors at Risk
The advisory identifies six sectors as most at risk: energy, communications, the defense-industrial base, healthcare, financial services, and local government. These are the sectors where a compromised router can provide access to industrial control systems, sensitive communications, or authentication infrastructure.
The Frost Armada Context
This advisory follows an international law enforcement operation that disrupted Frost Armada, a separate campaign attributed to APT28 (GRU unit 26165, also tracked as Fancy Bear). That operation had infected 18,000 routers across 120 countries by December 2025. Attackers altered DNS settings on compromised MikroTik and TP-Link SOHO routers to redirect authentication traffic to attacker-controlled servers and steal Microsoft 365 logins and OAuth tokens. The FBI remotely removed malicious DNS settings.
The two operations are distinct but complementary. Centre 16 targets enterprise and infrastructure routers for network access and espionage. APT28 targets SOHO routers for credential theft. Together, they represent a sustained Russian effort to compromise routing infrastructure at every tier.
Mitigation Measures
The advisory prescribes six specific actions:
- Upgrade to SNMPv3, which provides encryption and authentication that SNMPv1 and SNMPv2 lack.
- Disable Cisco Smart Install on all devices that do not require it.
- Enforce strong, unique passwords on all network equipment.
- Block TFTP and SNMP traffic at edge firewalls.
- Update software and firmware to current patched versions.
- Replace end-of-life devices that no longer receive security updates.
NCSC Director of National Resilience Jonathon Ellison stated, “The NCSC, alongside our international partners, have repeatedly exposed the advanced tools and coordinated campaigns of Russian cyber actors who persistently seek to exploit any vulnerability they encounter.”
What to Do
Patching is not enough for these attacks. The advisory targets a configuration weakness, not a single CVE. Every organization operating internet-facing routers should audit SNMP configurations, disable unnecessary management protocols, and verify that no devices accept default community strings. If you are running SNMPv1 or SNMPv2 on any internet-facing interface, you are running the exact configuration these attackers are scanning for.
Sources
Bleeping Computer: US and Allies Warn of Russian Critical Infrastructure Router Attacks, 13 Jul 2026 – https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
NCSC: UK and International Allies Urge Critical Sectors to Improve Defences Against Russian Intelligence Targeting, 13 Jul 2026 – https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting