
criticalCritical Infrastructure
FSB Center 16 Systematically Compromises Critical Infrastructure Networking Hardware to Pivot into OT Environments
Recent joint intelligence highlights a surge in FSB Center 16 activity targeting networking hardware to infiltrate OT/ICS environments across global energy and manufacturing sectors in July 2026.
19 July 2026Last updated 20 August 20266 min readCISA and NSA Joint Advisory
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
#FSB Center 16#OT/ICS Security#Edge Device Exploitation#Industrial Control Systems#Critical Infrastructure
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- CISA and NSA Joint Advisory
- Read Time:
- 6 min
Executive Summary\nOn July 15, 2026, a coalition of cybersecurity agencies from the United States, United Kingdom, Australia, and Canada issued a comprehensive joint advisory regarding ongoing disruptive activities by the Russian Federal Security Service (FSB) Center 16. The group, also tracked as Berserk Bear and Dragonfly, has significantly escalated its operations against global critical infrastructure, particularly focusing on the manufacturing and energy sectors. This campaign represents a shift toward exploiting the network perimeter—specifically edge devices and routers—to facilitate long-term persistence within Operational Technology (OT) and Industrial Control Systems (ICS) environments. Unlike previous years where zero-day exploits were the primary vehicle, this current wave relies on the systematic exploitation of weak security configurations and credential harvesting.\n\n## Threat Analysis\nFSB Center 16 is currently utilizing a high-volume approach to gain initial access. By scanning internet-facing infrastructure for vulnerable networking hardware, the actor identifies systems with default SNMP community strings, legacy management protocols, and unpatched firmware. Intelligence indicates that Center 16 is focusing on maintaining a low profile by 'living off the land,' using stolen administrative credentials to move laterally from Information Technology (IT) networks into isolated OT zones. The threat actor’s primary objective appears to be pre-positioning for potential future disruptive actions rather than immediate data theft, making this a significant strategic threat to national security and public safety.\n\n## Technical Details\nThe technical core of this campaign involves the exploitation of a massive credential leak affecting over 74,000 FortiGate devices, which occurred in late June 2026. Center 16 has deployed a custom Golang-based harvester to ingest approximately 110 million credentials. Once an edge device is compromised, the actors exfiltrate router configuration files to map internal network topology and identify downstream PLCs and HMIs. They specifically target devices running Modbus TCP and S7 protocols that are improperly bridged to the IT segment. Furthermore, the actors have been observed modifying DNS settings on MikroTik and TP-Link SOHO routers to redirect internal authentication traffic to attacker-controlled 'credential sinkholes,' allowing for the continuous theft of Microsoft 365 tokens and OAuth credentials.\n\n## Attribution Assessment\nEncrygma researchers, alongside partners at CISA and Mandiant, attribute this activity with high confidence to FSB Center 16 (also known as Energetic Bear). The attribution is based on the reuse of specific infrastructure previously linked to FSB operations, the overlap in Golang-based toolsets, and the distinct focus on industrial sectors that align with Russian strategic interests. While some operations use hacktivist fronts for deniability, the sophisticated nature of the network mapping and the scale of the credential harvesting operation point directly to a state-resourced intelligence agency.\n\n## Implications\nThe systemic compromise of edge devices that serve as the IT/OT boundary poses a critical risk. If attackers gain control over these routers, they can manipulate routing tables to bypass security controls or perform Man-in-the-Middle (MitM) attacks on ICS traffic. This could lead to the unauthorized manipulation of industrial processes, potentially resulting in equipment damage or loss of life in the energy and water sectors. Furthermore, the longevity of these compromises suggests that many organizations may have dormant threats residing in their network hardware for months before activation.\n\n## Recommendations\nTo mitigate this threat, Encrygma recommends the following: 1. Conduct an immediate audit of all internet-facing networking equipment and change all administrative credentials. 2. Disable all insecure management protocols, including legacy SNMP, Telnet, and HTTP, in favor of SNMPv3 and HTTPS. 3. Update all FortiGate and edge router firmware to the latest security patches to address recent credential leaks. 4. Implement hardware-backed multi-factor authentication (MFA) for all administrative logins. 5. Strictly enforce network segmentation between IT and OT environments, ensuring no direct routing exists between the public internet and industrial controllers.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room