FSB Center 16 is a Russian Federal Security Service cyber and signals-intelligence unit, also associated with Military Unit 71330, that has been linked to long-running espionage-focused intrusions against critical infrastructure and other strategic sectors worldwide. The activity is commonly tracked under multiple overlapping names, including Static Tundra, Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, and Ghost Blizzard, although some of these labels may refer to related clusters rather than a perfectly identical set of operations. The unit is known for targeting network infrastructure, especially internet-exposed and poorly secured routers and other networking devices, to obtain durable access, collect device configuration data, and enable follow-on reconnaissance and intrusion. Reported sectors at risk or previously targeted include energy, communications, defense industrial base, financial services, government services and facilities, healthcare and public health, and other critical infrastructure environments. The group has also been linked to campaigns affecting U.S. government entities, state and local organizations, aviation-related targets, and foreign energy organizations. A defining characteristic of Center 16 activity is opportunistic exploitation of weak or legacy network management exposure. Public reporting has tied the group to abuse of SNMP, particularly legacy SNMPv1 and SNMPv2 deployments using default or weak community strings, as well as exploitation of Cisco Smart Install and Cisco device vulnerabilities including CVE-2018-0171 and older Cisco flaws. The actors have been observed scanning broadly for exposed management services, abusing configuration-copy functionality to extract router and switch configurations, and in some cases modifying configurations to preserve unauthorized access. Observed tradecraft includes mass reconnaissance of internet-facing devices, theft of configuration files, use of compromised network devices as intermediate infrastructure, and persistence through configuration tampering or lower-level device modification. Reported persistence mechanisms include creation of highly privileged local accounts, weakening of remote administration controls, redirection or manipulation of centralized authentication, loading of modified system images, and bootloader-level persistence. The group has also been associated with techniques that facilitate passive traffic access, credential and topology discovery, proxying, and potential pivoting toward industrial control system and operational technology environments. Center 16’s operational focus on routers and similar appliances is strategically significant because these devices can provide visibility into network topology, routing relationships, access controls, credentials, and remote connectivity while often remaining outside traditional endpoint monitoring coverage. The unit’s activity is therefore assessed as primarily espionage-oriented, with particular emphasis on pre-positioning and intelligence collection against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Два вектора - SNMP и семилетняя CVE-2018-0171 в Cisco Smart Install... Уязвимость затрагивает Cisco IOS и IOS XE: некорректная валидация пакетов позволяет неаутентифицированному удалённому атакующему вызвать перезагрузку устройства (DoS) или выполнить произвольный код... Статус KEV: включена в каталог CISA Known Exploited Vulnerabilities с 3 ноября 2021 года - подтверждение активной эксплуатации.
The actors previously exploited at least the following CVEs: CVE-2018-0171, CVE-2008-4128. CVE-2008-4128 only affects end-of-life Cisco devices.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Long-running Russian state-linked cyber operations compromising routers and other network devices in critical infrastructure, using SNMP abuse and Cisco Smart Install exploitation to steal and modify device configurations, maintain persistence, and enable follow-on access into ICS/OT environments.
Russian FSB signals-intelligence unit conducting router compromises to spy on critical infrastructure.
FSB Center 16 is accused of orchestrating cyberattacks against U.S. critical infrastructure, including government agencies and energy firms, and exploiting vulnerabilities in Cisco devices.
Russian government-sponsored cyber actors exploiting poorly configured and vulnerable networking devices, especially routers, using SNMP scanning, configuration theft, TFTP/FTP transfer of device configs, and occasional exploitation of Cisco-related vulnerabilities and management interfaces across critical infrastructure sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.