“U.S. and allies warn Russian hackers are targeting critical infrastructure routers” – Experts Perspectives

Cybersecurity agencies from the U.S. and allied countries warned that hackers linked to Russia’s Federal Security Service are exploiting vulnerable and poorly configured routers to access critical infrastructure networks. Targeted sectors include communications, energy, financial services, healthcare, government and the defense industrial base.
The hackers scan for internet-connected routers using default or weak SNMP credentials, then copy device configuration files and transfer them to attacker-controlled servers. They have also exploited Cisco Smart Install and known Cisco vulnerabilities.
The advisory recommends disabling Cisco Smart Install and older SNMP versions, using SNMPv3, replacing default credentials, blocking unnecessary SNMP and TFTP traffic, updating software and firmware, and replacing end-of-life devices.

Experts from Black Hills Information Security, Inc., BreachLock, Suzu Labs, and Finite State offer perspectives on the matter.

John Strand, Owner, Black Hills Information Security, Inc.:

“The story isn’t the vulnerability itself. Attacking things like Cisco Smart Install or abusing SNMP isn’t new. Security teams have known about these techniques for more than a decade. The real story is that nation-state attackers continue to succeed by exploiting problems organizations should have fixed years ago.

“Every time we see a large nation-state campaign, there’s a temptation to focus on the newest exploit or the most sophisticated technique. In reality, these campaigns are often built around vulnerabilities and insecure configurations that have been public knowledge for years. Attackers aren’t succeeding because defenders lack intelligence. They’resucceeding because too many organizations still struggle with the fundamentals of computer security.

“My biggest concern isn’t the technical details of this attack. It’s that the organizations most at risk probably aren’treading the advisories, following security news, or tracking CISA alerts. We spend a lot of time talking to security professionals who are already engaged, but the organizations that need the message most often aren’t part of that conversation. Until we find better ways to reach those organizations, attackers will continue to find easy wins using vulnerabilities we’ve known about for years.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Router infrastructure is one of the most consistently overlooked parts of an attack surface, and adversaries like FSB-linked actors know this. When you can pull a device config file over SNMP using the string ’public’, you have a map of the internal network handed to you before you’ve done anything sophisticated. SNMPv3 with authentication and encryption, disabling Smart Install, blocking TFTP externally, and cycling out end-of-life hardware are not complicated fixes, but they require someone to actually own that work inside the organization, and that ownership gap is where the exposure lives.”

Denis Calderone, CTO, Suzu Labs:

“I’ve personally been pulling router configs with Cisco Smart Install during penetration tests for years. One unauthenticated request to TCP 4786 and the switch hands over its startup config, credentials, SNMP community strings, TACACS+ keys, all of it. So, when the FBI warns that Russia’s FSB is doing the exact same thing against US critical infrastructure, the only thing that surprises me is that anyone still has this feature running. CVE-2018-0171 was patched in 2018 and Cisco has been telling people to disable Smart Install since 2017. It’s even been in the CISA KEV catalog since 2021. There just isn’t any excuse for this.

“And then there’s SNMP exposed on the internet. Static Tundra is gaining initial access using community strings like "public" and "anonymous" with read-write permissions. What is SNMP doing exposed to the internet in 2026? SNMPv2 doesn’t even encrypt the community string. Once they’re in, they pull the config, harvest credentials, come back through SNMP or SSH, create privileged local accounts, modify TACACS+ to break remote logging, and in some cases deploy the SYNful Knock firmware implant that persists through reboots. By the time the device is fully compromised, its own audit trail is under the attacker’s control. And the FBI confirmed they’re doing ICS protocol reconnaissance after gaining access, which tells you exactly what they’re building toward.

“The fix is straightforward. Run "no vstack" on every Cisco switch in your environment today. If you don’t know whether Smart Install is enabled, assume it is, because it was enabled by default on older IOS releases. Disable SNMP on anything reachable from outside your management VLAN, and if you still need it, v3 with authentication and encryption is the minimum. If you’re running end-of-life gear that can’t accept the patch, those devices need to be on an active replacement plan, not a someday list. Static Tundra has maintained access to some environments for years without detection. Every day an unpatched router sits on your network with Smart Install enabled is another day the config is available to anyone who asks for it.”

Doc McConnell, Head of Policy and Compliance, Finite State:

“Over and over again, we see the same story playing out: infrastructure essential to public health and economic stability being successfully compromised by nation-state adversaries. Telecommunications, hospitals, state governments, energy infrastructure, and even the defense industrial base — all under attack for over a decade. And the second part of the story is also the same: the attackers are scanning for well-known vulnerabilities and using default or common credentials to access these systems.

“The defensive posture remains the same: infrastructure operators must disable insecure protocols like Cisco’s Smart Install feature and SNMPv1 and v2, implement strong and unique passwords on all their devices, and restrict and monitor access to their management protocols.

“We have to do better. Our national security is at stake.”

Articles similaires

Special Reports

1 September 2026

New Cequence & EMA Research: 94% of Enterprises Trust Their AI Agents Aren’t Over-Provisioned Yet Only 33% Actually Enforce It

Survey of IT and Security Leaders reveals standing permissions and delayed authorisation checks (…)

Special Reports

4 August 2026

UK police database breach exposes data of 100K+ officers and staff – Expert Perspectives

The Police National Legal Database (PNLD), a legal reference service used by all 43 Home Office (…)

Special Reports

13 July 2026

“U.S. and allies warn Russian hackers are targeting critical infrastructure routers” – Experts Perspectives

Cybersecurity agencies from the U.S. and allied countries warned that hackers linked to Russia’s (…)