An unprecedented coalition of US, UK, Canada, Australia, New Zealand, and five EU nations recently issued a joint advisory, titled “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting.” The document explicitly names Russia’s FSB Center 16, a state threat group tied to years’ worth of aliases already tracked separately by the industry. The advisory frames the current threat as a continuation of activity first flagged in 2025, rather than a new campaign. The scale of the collaborative response signals how seriously allied governments now weigh router-level compromise.
Patience as Tradecraft
The threat group—tracked under names including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra—uses a variety of methods to carry out their campaigns. Bad actors scan global IP space for Simple Network Management Protocol (SNMP) agents that still accept default or commonly used community strings to authenticate. They use spoofed IP addresses to mask the true origin of scanning traffic in device logs.
SNMP Set-Requests instruct devices to copy their own configuration files, without the need for malware involvement. Trivial File Transfer Protocol (TFTP) exfiltration to actor-controlled virtual private servers (VPS) turns the 40-year-old protocol into a getaway car for bad actors. The combination of these methods makes it possible for attackers to evade common defenses and achieve successful payouts.
The tactics used by this and many other groups demonstrate the adversarial importance of tried-and-true methods taking advantage of longstanding gaps. “The most important takeaway from this campaign is that sophisticated adversaries continue to exploit relatively basic weaknesses because they know those weaknesses still exist,” according to Louis Eichenbaum, Federal CTO at ColorTokens, a San Jose, Calif.-based provider of Zero Trust microsegmentation solutions. “This is especially true with our OT systems that manage our critical infrastructure as they often use legacy components. Default credentials, exposed management interfaces, and flat networks remain common across critical infrastructure.”
What a Config File Buys
Using the access and files obtained with this method, threat actors can achieve a range of further malicious actions. Router configs often contain weakly hashed or plaintext credentials, unlocking deeper access for attackers. Compromised routers become footholds into a wide variety of critical sectors, including energy, healthcare, finance, and defense networks.
The targeting of these attacks is opportunistic rather than bespoke. These threat actors choose their victims based on discovered misconfigurations, not targeted based on identity or specifically sought payouts. The campaign demonstrates an occasional pivot to known Cisco CVEs and Smart Install abuse when leveraging SNMP alone proves insufficient.
A Shared Playbook
The advisory points out that the tactics, techniques, and procedures (TTPs) used by FSB Center 16 are not unique to this single threat group, or to Russian state-sponsored actors. It explicitly notes marked overlap between FSB Center 16 methods and activity observed by likely Chinese state-sponsored group Salt Typhoon. The phenomenon of distinct state actors from different countries converging on the same soft targets suggests not a one-off gap in security, but a systemic weakness.
This convergence comes with both positive and negative impacts. The sharing of tactics means that mitigations designed to protect against one nation-state actor can now double as defenses against the other. It also raises the uncomfortable question of how many other threat actors globally are already inside via the same door. “The techniques in this advisory are not new; however, the breadth of international attribution should remove any doubt that this remains an active and coordinated threat to critical infrastructure,” says Matthew Hartman, Chief Strategy Officer at Merlin Group, a Tysons Corner, Virginia-based network of affiliates that invests in, enables, and scales cyber technology companies.
Hygiene as Strategy
The fixes recommended in the advisory are unglamorous security steps: using SNMPv3, disabling legacy protocols, and enforcing strong credential hygiene. The United States Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) offer free services as low-friction starting points for protecting against these threats. The real message of the advisory is that sophistication is not the threat model that most organizations need to prepare for. This decade-old campaign persists and continues to pay off not because the threat has evolved, but because defenses have stayed the same.