
criticalCritical Infrastructure
Russian FSB Center 16 Targets Global Critical Infrastructure via Widespread Networking Device Exploitation
Joint global advisory warns that Russian FSB Center 16 is compromising routers across energy and water sectors using SNMP exploits and legacy vulnerabilities to establish persistent access for potential sabotage.
18 July 2026Last updated 20 August 20265 min readCISA / FBI / NSA Joint Advisory
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- North America / Europe / Oceania
- Confidence:
- High Confidence
- CVE:
- CVE-2018-0171, CVE-2008-4128
- Source:
- CISA / FBI / NSA Joint Advisory
- Read Time:
- 5 min
Executive Summary On July 16, 2026, a coalition of sixteen international cybersecurity agencies, including CISA, the FBI, and the NSA, issued a high-priority joint advisory regarding an ongoing campaign by Russian Federal Security Service (FSB) Center 16. This threat actor, widely known as Berserk Bear or Dragonfly, is actively scanning for and exploiting poorly secured edge networking devices—primarily routers—within the critical infrastructure sector. Affected industries include energy, water treatment, communications, and the defense industrial base. The campaign emphasizes long-term persistence and the exfiltration of network configuration files, which could serve as a precursor to disruptive operations. Simultaneously, reporting from the last 24 hours indicates secondary pressure on the energy sector, following claims by the World Leaks ransomware group regarding data exfiltration from the Kudankulam nuclear facility, highlighting a multi-vector threat landscape for 2026. ## Threat Analysis The current campaign demonstrates a strategic shift toward infrastructure pre-positioning. Rather than traditional phishing, Center 16 is leveraging the inherent trust in networking hardware. By compromising SOHO and enterprise-grade routers, the actors create a covert proxy network that enables lateral movement while evading standard endpoint detection. This 'Living-off-the-Network' strategy allows for the silent mapping of Industrial Control System (ICS) environments. The focus on stealing SNMP configuration data and network diagrams indicates a high-level intent to understand the physical and logical boundaries of SCADA networks, particularly in the energy and water sectors. Unlike financially motivated actors, Center 16 prioritizes stealth to maintain access for future strategic leverage. ## Technical Details The primary attack vector involves the use of Simple Network Management Protocol (SNMP) set-requests. The actors scan public-facing IP ranges for devices responding to default or common community strings. Once a vulnerable device is identified, they issue commands to copy the device’s running configuration to a remote virtual private server (VPS) via the Trivial File Transfer Protocol (TFTP). Furthermore, the group is aggressively exploiting legacy vulnerabilities, specifically CVE-2018-0171 and CVE-2008-4128, which affect the Cisco Smart Install feature. These exploits allow for arbitrary command execution on the target routers. In some instances, the actors have replaced legitimate firmware with modified versions containing persistent backdoors, ensuring access remains even after a system reboot or password change. Analysts have also observed the use of valid administrative credentials harvested through previous compromises to pivot into segmented OT zones. ## Attribution Assessment With high confidence, this activity is attributed to the Russian FSB’s Center 16, also tracked by industry as Berserk Bear, Ghost Blizzard, and Static Tundra. The TTPs align perfectly with historical 'Dragonfly' operations that targeted European and North American energy grids between 2017 and 2024. The multi-national coordination of this warning reflects the scale of the threat and the consistency of the indicators of compromise (IOCs) observed across multiple jurisdictions, including the United States, United Kingdom, Australia, and Canada. ## Implications The compromise of network infrastructure at this scale poses a critical risk to national security. By controlling the routers that facilitate communication between IT and OT segments, Center 16 can intercept sensitive data, redirect traffic, or perform man-in-the-middle attacks on HMI-PLC communications. The exfiltration of configuration files provides the adversary with a roadmap for future sabotage. If activated during a period of geopolitical tension, these footholds could be used to disrupt power distribution or manipulate water treatment chemicals, leading to significant public harm. The breadth of the campaign suggests that no operator using legacy networking equipment is outside the adversary's reach. ## Recommendations Critical infrastructure operators are urged to take immediate action. First, disable the Cisco Smart Install feature on all networking hardware. Second, transition from SNMPv1/v2 to SNMPv3 with modern encryption and strong authentication. Third, enforce strict egress filtering to block unauthorized TFTP and SNMP traffic to external IP addresses. Finally, organizations must conduct an immediate review of router configuration files for unauthorized changes or the presence of suspicious GRE tunnels. Regular firmware integrity checks and the implementation of hardware-based MFA for administrative access are essential to mitigate this persistent threat.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News RoomRelated Intelligence

Iran-Linked Cyber Actors Escalate Attacks on UK and US Critical Infrastructure
01 Sep 2026

US Declares National Emergency as Foreign-Linked Cyberattacks Target Critical Power and Water Infrastructure
28 Aug 2026

FBI Neutralizes Chinese "QTFY" Proxy Network Targeting US Federal Agencies and Critical Infrastructure
28 Aug 2026
