The FBI and IC3 warned that cyber actors linked to the Russian Federal Security Service's Center 16 targeted networking devices at U.S. and global organizations, including critical infrastructure operators, by exploiting exposed SNMP services and end-of-life equipment vulnerable to the Cisco Smart Install flaw CVE-2018-0171. Investigators said the actors collected configuration files from thousands of devices associated with U.S. entities and, in some cases, modified device configurations to establish unauthorized access.
The intrusions were tied to activity tracked as Berserk Bear and Dragonfly, continuing a long-running Russian campaign focused on compromising network infrastructure as a foothold into victim environments. After accessing edge devices, the actors reportedly conducted internal reconnaissance and showed interest in industrial control system-related protocols and applications, while U.S. authorities urged organizations to inspect networking devices for configuration changes or malware, review older Cisco infrastructure, and report suspected compromises to the FBI or IC3.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The United States and 12 partner countries issued a joint cybersecurity advisory warning that Russian state-sponsored hackers tied to FSB Center 16 were compromising critical infrastructure worldwide via poorly configured and vulnerable networking devices. The advisory cited tactics including weak or default passwords, Cisco Smart Install abuse, and exploitation of CVE-2008-4128 and CVE-2018-0171, and said affected sectors included defense, communications, energy, financial services, government, and healthcare.
A cybersecurity information sheet was released with defensive guidance aimed at reducing the risk of SNMP abuse on network devices. The document represents a technical mitigation step related to the broader campaign targeting vulnerable or misconfigured networking infrastructure.
The US State Department announced a $10 million reward for information on Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov, who US authorities accused of conducting cyber operations against critical infrastructure on behalf of Russia's FSB Center 16. The action publicly tied the men to the long-running campaign exploiting Cisco Smart Install flaw CVE-2018-0171 and targeting energy and other critical infrastructure organizations worldwide.
IC3 published a public service announcement about Russian government cyber actors targeting networking devices and critical infrastructure. The notice aligns with the FBI warning on the same activity and serves as a public reporting and awareness action.
The FBI warned that cyber actors attributed to the Russian Federal Security Service's Center 16 were targeting computer networks and critical infrastructure in the United States and globally. The alert said the actors exploited SNMP and end-of-life devices vulnerable to CVE-2018-0171, collected configuration files from thousands of devices tied to U.S. entities, altered some configurations for unauthorized access, and conducted reconnaissance including interest in ICS-related protocols.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
waterisac.org
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcecyberscoop.com
Open sourceic3.gov
Open sourcefbi.gov
Open sourcemedia.defense.gov
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.