logo

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

ID: a40c345b-6c7a-58e8-b649-ffd5bb684672

STIX ID: report--a40c345b-6c7a-58e8-b649-ffd5bb684672

Feed Name: ASD's ACSC - Advisories RSS

Threat Score
90/100

Date Published: 2026-07-13

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

This joint international advisory warns that Russian FSB Center 16 actors are actively scanning for and exploiting poorly configured networking devices—especially routers—by abusing SNMP (default/community strings), Cisco Smart Install, and known CVEs to copy and exfiltrate device configurations (often via TFTP) to actor-controlled servers; the advisory maps these TTPs to MITRE ATT&CK, identifies at-risk critical infrastructure sectors, lists example OIDs and IOCs, and provides prioritized mitigations such as enabling SNMPv3, disabling Smart Install, blocking management ports, enforcing strong credential storage, and updating device firmware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.