News Room
16
Share
EU and UK Impose Sweeping Sanctions on Russian FSB Center 16 Following Global Router Exploitation Campaign
criticalState Cyber Warfare

EU and UK Impose Sweeping Sanctions on Russian FSB Center 16 Following Global Router Exploitation Campaign

International authorities have sanctioned 24 entities linked to Russia's FSB Center 16 following a massive campaign targeting global telecommunications and energy infrastructure using edge device exploits.

14 July 2026Last updated 20 August 20264 min readNCSC / CISA / Mandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Critical
Actor Type:
Nation-State
Geography:
Europe and North America
Confidence:
Confirmed
Source:
NCSC / CISA / Mandiant
Read Time:
4 min

Executive Summary

On July 13, 2026, the European Union and the United Kingdom announced a comprehensive package of sanctions and a joint cybersecurity advisory targeting the Russian Federal Security Service (FSB) Center 16. This coordinated action follows a multi-year investigation into a persistent cyberespionage and sabotage campaign aimed at undermining European and North American critical infrastructure. The sanctions target nine individuals and four primary entities, including the GRU-linked firm 'Impuls,' which provided technical support for destructive operations. This diplomatic escalation coincides with a fresh technical warning from twelve countries regarding ongoing Russian efforts to compromise global routing infrastructure.

Threat Analysis

FSB Center 16, also tracked by the private sector as 'Berserk Bear,' 'Dragonfly,' and 'Ghost Blizzard,' has shifted its focus toward wide-scale opportunistic exploitation of edge networking devices. Unlike targeted spear-phishing, this campaign utilizes automated scanning to identify vulnerable internet-facing routers. The primary objective is twofold: establishing long-term persistence for strategic intelligence collection and pre-positioning for disruptive actions. Intelligence indicates that these actors successfully compromised portions of Poland’s energy grid in late 2025, an operation that was narrowly contained before causing widespread blackouts. The group’s current activity demonstrates a high level of operational agility, moving away from custom malware in favor of abusing legitimate administrative protocols.

Technical Details

Recent telemetry reveals that Center 16 actors are systematically scanning for devices using default or weak Simple Network Management Protocol (SNMP) community strings. By gaining access to SNMP, attackers use specific Object Identifiers (OIDs) to command routers to copy their running configurations. These configurations are then exfiltrated via Trivial File Transfer Protocol (TFTP) to actor-controlled Virtual Private Servers (VPS).

Furthermore, the group has been observed exploiting legacy vulnerabilities in Cisco and Ivanti gateways to deploy custom web shells. Once internal access is secured, the actors utilize 'Living off the Land' (LotL) techniques, specifically abusing PowerShell and legitimate credential-stealing tools like 'Lumma Stealer' to harvest internal network maps. The use of code-signed binaries—some utilizing stolen certificates from South Korean gaming companies—allows their persistence mechanisms to bypass standard EDR (Endpoint Detection and Response) solutions.

Attribution Assessment

Cybersecurity agencies have attributed these activities to FSB Center 16 with high confidence. The attribution is based on a combination of infrastructure overlaps with previous 'Dragonfly' campaigns and the unique formatting of the exfiltrated configuration data. The involvement of 'Impuls,' a Moscow-based technical firm, was confirmed through signals intelligence indicating they recruited specialists specifically to support GRU Unit 29155 and FSB hybrid operations. The EU's High Representative for Foreign Affairs has officially designated this network as a primary driver of Russia’s strategy to destabilize international partners.

Implications

The scope of these operations suggests that Russia remains committed to maintaining a 'persistent presence' within Western critical infrastructure. The ability to exfiltrate router configurations provides the Kremlin with a blueprint of internal networks, enabling much faster lateral movement during a potential kinetic conflict. The targeting of heating and power plants in Northern Europe underscores the risk of cyber-physical sabotage as a tool of geopolitical coercion.

Recommendations

Organizations, particularly those in the energy, water, and telecommunications sectors, should implement the following mitigations immediately:

  1. SNMP Hardening: Disable SNMP if not required. If necessary, move to SNMPv3 with strong authentication and encryption, and change all default community strings.

  2. Edge Device Auditing: Review all edge router and VPN concentrator logs for unauthorized configuration copy commands or unusual TFTP traffic.

  3. Credential Rotations: Conduct a mandatory reset of administrative credentials for all networking hardware, ensuring Multi-Factor Authentication (MFA) is strictly enforced for all management interfaces.

  4. Patch Management: Prioritize patching for known exploited vulnerabilities in Cisco, Fortinet, and Ivanti edge products, as these remain the primary entry points for Center 16 actors.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo