Russian State-Sponsored Attackers Exploit Cisco Routers
ID: c8d90af2-b7a5-53db-bbfa-065128495016
STIX ID: report--c8d90af2-b7a5-53db-bbfa-065128495016
Feed Name: Cyble Blog
**Executive Summary:** The advisory describes how CVE-2017-6742, an SNMP buffer overflow in affected Cisco IOS and IOS XE versions, has been exploited by APT28 to deploy the Jaguar Tooth malware that patches authentication functions for backdoor access and performs automated device reconnaissance and TFTP exfiltration; the report lists affected MIBs/versions, device exposure estimates, recommended mitigations (restrict SNMP, monitor hosts, and apply patches), and emphasizes urgent remediation to prevent unauthorized control of routers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
