Center 16 is a cyber and signals intelligence unit of Russia’s Federal Security Service (FSB) that has been publicly linked to long-running state-sponsored cyber operations against critical infrastructure and government-related targets. It is widely tracked under multiple aliases, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. Public reporting describes Center 16 as an FSB signals intelligence element engaged in espionage-oriented network compromise and, in some cases, activity assessed as attempted sabotage against critical infrastructure. The group has been associated with more than a decade of targeting against organizations in the communications, defense industrial base, energy, financial services, government, and healthcare sectors across the United States, Europe, and other allied countries. It has been specifically tied to campaigns against routers, switches, and other edge networking devices, as well as to attempted disruptive operations affecting Poland’s energy sector and water treatment facilities. Center 16’s tradecraft is characterized by opportunistic exploitation of weak security hygiene rather than exclusively novel capabilities. Reported techniques include large-scale internet scanning for exposed network infrastructure, abuse of default, weak, or reused credentials, exploitation of insecure or legacy SNMP configurations, compromise of web-based management interfaces, and abuse of Cisco Smart Install. The group has also been linked to exploitation of known Cisco vulnerabilities, including CVE-2008-4128 and CVE-2018-0171. Once access is obtained, operators have been reported to harvest device configurations and credentials, monitor and redirect traffic, maintain persistence on compromised infrastructure, and pivot deeper into victim environments. Compromise of perimeter network devices by Center 16 can support multiple operational objectives, including intelligence collection, credential theft, covert access, traffic interception, and enabling follow-on intrusion activity inside enterprise or operational networks. The actor’s focus on poorly secured routers and similar infrastructure reflects a persistent emphasis on overlooked but strategically valuable network choke points. Center 16 is assessed as a Russian state actor operating on behalf of the FSB. Public attributions by Western governments have connected it not only to espionage against ministries, diplomatic entities, and defense-linked organizations, but also to increasingly severe operations affecting public services and critical national infrastructure. Known references to sub-elements include FSB Unit 61240, which has been identified in connection with targeting of France.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state-backed cyber unit opportunistically targeting poorly secured routers and network devices worldwide, using SNMP scanning, weak/default/reused credentials, outdated protocols, known Cisco vulnerabilities, Cisco Smart Install weaknesses, and web management portal flaws to compromise routers for traffic monitoring, redirection, credential theft, persistence, and deeper network access.
Conducting opportunistic intrusions into critical infrastructure networks worldwide by exploiting weak router credentials, outdated networking technology, Cisco Smart Install, web management portals, and Cisco vulnerabilities. The group was also formally blamed for a failed December 2025 cyberattack against Poland’s energy grid.
FSB-linked operators are conducting ongoing intrusions into critical infrastructure networks worldwide by exploiting weak credentials, outdated networking devices, Cisco Smart Install, web management portals, and Cisco vulnerabilities.
Conducting long-running attacks against critical network infrastructure by scanning for poorly configured network devices, exploiting Cisco Smart Install and network management web portals, and stealing device configurations and credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.