Russia-linked APT28 exploited poorly maintained Cisco routers worldwide for reconnaissance and malware deployment, according to a joint UK NCSC, US NSA, CISA and FBI advisory. The agencies assessed that APT28 is almost certainly Russia’s GRU Military Intelligence Unit 26165. The campaign, conducted in 2021, targeted devices in Europe, US government institutions and approximately 250 Ukrainian victims. Attackers used weak SNMP community strings for reconnaissance and exploited CVE-2017-6742. On some routers, they deployed Jaguar Tooth, which collected device and network information, exfiltrated it over TFTP and enabled unauthenticated backdoor access.
The agencies recommended patching affected routers, restricting SNMP access, replacing unencrypted management protocols and monitoring device commands. Potentially compromised devices require replacement of firmware and keys. The disclosure followed earlier government action addressing Russian cyber operations: the UK imposed sanctions over the attack on Germany’s parliament in 2020, and a 2021 US defense advisory addressed a GRU global brute-force campaign. For defenders, the router campaign underscores the need to secure network infrastructure as an espionage target, rather than focusing solely on endpoints and user accounts.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
The NCSC, NSA, CISA and FBI published a joint advisory detailing the 2021 campaign and assessing APT28 as almost certainly Russia's GRU Military Intelligence Unit 26165. An accompanying NCSC Jaguar Tooth analysis provided indicators of compromise and technical details, while the advisory recommended patching and hardening router management.
During the campaign, APT28 exploited CVE-2017-6742 and deployed Jaguar Tooth on some targeted routers. The malware collected device and network information, exfiltrated it over TFTP and enabled unauthenticated backdoor access.
APT28 used infrastructure to disguise SNMP access and exploited weak community strings, including the default string 'public', to collect router information and enumerate interfaces. Targets included routers in Europe, US government institutions and approximately 250 Ukrainian victims.
An attempted attack targeted the Organisation for the Prohibition of Chemical Weapons. The NCSC subsequently attributed it to APT28 and described its objective as disrupting independent analysis of chemicals weaponised by the GRU in the UK.
Cisco announced CVE-2017-6742, tracked internally as CSCve54313, and made patched software available. Its advisory also provided workarounds, including restricting SNMP access to trusted hosts or disabling specified Management Information Bases.
Cyberattacks against the German parliament involved data theft and disruption of email accounts belonging to German MPs and the Vice Chancellor. The NCSC subsequently attributed the attacks to APT28.
The UK government reported enforcing new sanctions against Russia for the cyberattack on the German parliament.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
ncsc.gov.uk
Open sourcegov.uk
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.