Categories: Cyber Security News

FBI Warns of Russian Government Hackers Attacking Networking Devices of Critical Infrastructure

The Federal Bureau of Investigation has issued a critical security alert regarding sophisticated cyber operations conducted by Russian Federal Security Service (FSB) Center 16, targeting networking infrastructure across the United States and globally.

The threat actors have been exploiting vulnerable networking devices to gain unauthorized access to critical infrastructure systems, demonstrating a calculated approach to compromising essential services.

The campaign leverages an unpatched vulnerability, CVE-2018-0171, found in Cisco Smart Install (SMI) protocol implementations alongside Simple Network Management Protocol (SNMP) weaknesses.

Sponsored

These attack vectors allow the threat actors to remotely access end-of-life networking devices that lack current security patches, creating persistent entry points into targeted networks.

FBI analysts identified that the threat actors have successfully collected configuration files from thousands of networking devices associated with US entities across multiple critical infrastructure sectors.

The scope of this operation reveals a systematic approach to mapping network architectures and identifying high-value targets within industrial control systems.

The FSB Center 16 unit operates under several aliases known to cybersecurity professionals, including “Berserk Bear,” “Dragonfly,” and more recently identified as “Static Tundra” by Cisco Talos researchers.

This threat group has maintained operations for over a decade, consistently targeting devices that accept legacy unencrypted protocols.

Configuration File Manipulation and Persistence Mechanisms

The attack methodology centers on sophisticated configuration file manipulation techniques that enable long-term persistence within compromised networks.

Sponsored

Once initial access is achieved through the CVE-2018-0171 vulnerability, the threat actors systematically modify device configuration files to establish backdoor access mechanisms.

These modifications are carefully crafted to blend with legitimate network configurations, making detection challenging for standard security monitoring tools.

The actors demonstrate particular interest in protocols and applications commonly associated with industrial control systems, suggesting strategic targeting of operational technology environments.

By maintaining access through modified configuration files, the threat group can conduct extended reconnaissance operations while remaining undetected within victim networks.

This persistent access method allows the attackers to monitor network traffic patterns, identify critical system dependencies, and potentially position themselves for future disruptive operations against essential infrastructure services.

Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

The post FBI Warns of Russian Government Hackers Attacking Networking Devices of Critical Infrastructure appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

City ‘cornerstone’ of public works retires with decades-long legacy of transportation projects

March 11, 2026 Building the first new interchange in 15 years close to the confluence…

36 minutes ago

News alert: Qevlar AI raises $30M to turn security alerts into actionable defense insights across SOCs

PARIS, March 10, 2026 — Qevlar AI, a leader in AI for transforming security operations…

41 minutes ago

Millenarian Fantasies

In Beirut, we start our days with the latest litany of places and people hit…

41 minutes ago

Independent product designer Allan Buntoengsuk uses GreatPen.xyz to share product, UX, and software design work

GreatPen.xyz – Squarespace customer – (United States) The .xyz community includes independent designers and creatives…

41 minutes ago

Australia’s National Film and Sound Archive Acquires World’s First Licensed Star Wars Pinball Machine

The National Film and Sound Archive (NFSA) of Australia has today announced it has acquired…

1 hour ago

Pluralistic: AI “journalists” prove that media bosses don’t give a shit (11 Mar 2026)

Today's links AI "journalists" prove that media bosses don't give a shit: In case there…

1 hour ago

This website uses cookies.