On July 13, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with several national and international agencies, released a joint Cybersecurity Advisory (CSA) detailing how adversaries associated with the Russian Federal Security Service (FSB)’s Center 16 continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks by targeting internet-exposed network infrastructure.
The advisory expands on the Federal Bureau of Investigation (FBI)’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure announcement by providing additional Tactics, Techniques, and Procedures (TTPs) to enable defenders to more fully understand and counter the threat.
The Federal Security Service (FSB) is Russia’s principal domestic security and counterintelligence agency, established in 1995 as the primary successor to the Soviet-era Committee for State Security (KGB). The FSB’s Center 16, also known as Military Unit 71330, is responsible for Signals Intelligence (SIGINT) and Communications Intelligence (COMINT), while also supporting offensive cyber operations.
Activity attributed to FSB’s Center 16 has been associated with multiple threat clusters tracked by the cybersecurity community under different names including Turla, DragonFly, Berserk Bear, Energetic Bear, Venomous Bear, Secret Blizzard, Ghost Blizzard, Static Tundra, and Crouching Yeti. Collectively, these threat clusters have frequently targeted organizations across the Communications, Defense Industrial Base, Energy, Financial Services, Government Services and Facilities, and Healthcare and Public Health sectors.
Center 16 operators primarily use scanning to identify poorly configured networking devices, particularly routers, for exploitation. Their preferred technique involves locating devices exposing Simple Network Management Protocol (SNMP) services that accept default or common community strings for authentication. These scans, run via proxies, consist of SNMP Set-Requests from a spoofed IP address containing Object Identifiers (OIDs) that instruct the SNMP agent on poorly configured networking devices to:
- Copy its configuration to a file, often called “config.bkp” or “output.txt”.
- Transfer the file, typically using Trivial File Transfer Protocol (TFTP), to an actor-controlled leased virtual private server (VPS) or compromised FTP server.
While SNMP scanning is the primary method the actors use to discover and exploit poorly configured networking devices, they occasionally exploit Common Vulnerabilities and Exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices. Previous operations have included the exploitation of vulnerabilities such as CVE-2018-0171 and CVE-2008-4128.
Given the longevity and operational maturity of FSB Center 16, AttackIQ recommends executing the following emulations that replicate the Tactics, Techniques, and Procedures (TTPs) commonly associated with this threat activity:
Berserk Bear – 2025-12 – Associated Tactics, Techniques and Procedures (TTPs)
This emulation contains the post-compromise Tactics, Techniques, and Procedures (TTPs) exhibited by Berserk Bear during the coordinated cyberattacks targeting Poland’s energy infrastructure on 29 December 2025.
Turla – 2023-01 – Reconnaissance Campaign Against Entities and Individuals in Ukraine
This emulation replicates the sequence of Tactics, Techniques, and Procedures (TTPs) exhibited by Turla during an activity reported in September 2022, in which the adversary targeted individuals and organizations in Ukraine.
[CISA AA23-129A] Turla – Hunting Russian Intelligence “Snake” Malware
This emulation was released in response to CISA Advisory AA23-129A on May 10, 2023. It replicates the sequence of Tactics, Techniques, and Procedures (TTPs) exhibited by Turla during a campaign involving Snake, an espionage tool designed to collect sensitive intelligence from high-priority targets, such as government networks, research facilities, and journalists.
Detection and Mitigation Opportunities
AttackIQ strongly recommends reviewing and following CISA’s recommendations, provided in the advisory, to aid in detecting and mitigating fast flux activity. These steps can help organizations identify and mitigate the risks associated with fast flux networks and improve overall cybersecurity posture.
The authoring agencies highly recommend network defenders implement the following mitigations to harden networks against this exploitation:
- Disable Cisco Smart Install on all devices.
- Use SNMPv3 with “authPriv” configured to the most modern encryption standard that is supported by the device instead of SNMPv1 or SNMPv2.
- Disable SNMPv1 and SNMPv2. These are legacy protocols and should no longer be needed on current devices. If they are necessary, change all community strings from defaults and only allow read-only community strings rather than read-write access.
- SNMPv3 adds strong authentication and data encryption that are unavailable in SNMPv1 and v2. SNMPv3 replaces clear text shared passwords, known as community strings, with more securely encoded parameters, and authenticates and encrypts data.
- Use strong, unique passwords for local accounts on network devices and configure credentials to be stored securely to prevent reuse of compromised passwords.
- Cisco devices protect passwords in the configuration file using different hashing types. Use hashing type 8 for user credentials. Avoid using hashing type 0, 4, and 7 as they are insecure or store passwords in plaintext in the configuration file.
- Monitor for unusual credentials that do not conform to standard organizational naming conventions.
- Monitor for and alert on logins using local accounts. Local accounts should only be used in emergency situations when accounts supported by centralized authentication servers are unavailable. Centralized authentication to network devices should support multi-factor authentication where feasible.
- Monitor and restrict access to SNMP OIDs using a Management Information Base (MIB) allow list. Reference the vendor-specific MIB for the network devices and monitor OIDs for indications of reconnaissance or misconfiguration in logs or intrusion detection systems (IDS). IDS rules should be written for inbound SNMP Set-Requests that contain OIDs targeting sensitive device data.
- Example OIDs include:
- 1.3.6.1.4.1.9.9.96.1.1 (Cisco Config Copy)
- 1.3.6.1.4.1.9.9.96.1.1.1.1.5 (Config Copy Server Address, value for this OID is where the configuration file is being sent to)
- Example OIDs include:
- Restrict management protocols.
- Use Access Control Lists (ACLs) to only allow management protocols, such as SNMP, from management devices, preferably on an out-of-band network.
- On edge firewalls and devices deny all external communications on the following ports unless mission critical, with strict monitoring if blocking is not feasible:
- User Datagram Protocol (UDP) port 69 (TFTP)
- Transmission Control Protocol (TCP) port 4786 (SMI)
- UDP ports 161 and 162 (SNMP)
- TCP/UDP ports 10161 and 10162 (SNMPv3)
- Update network device software and firmware images, especially to patch known vulnerabilities, and upgrade end-of-life devices to supported ones.
- Use an attack surface management service to identify and secure Internet-facing systems with weak configurations and known vulnerabilities.
- U.S.-based federal, state, local, tribal, and territorial governments and U.S. critical infrastructure organizations should consider signing up for CISA’s no-cost Cyber Hygiene services.
- U.S. Defense Industrial Base organizations should consider signing up for NSA’s DIB Cybersecurity Services.
- Use an attack surface management service to identify and secure Internet-facing systems with weak configurations and known vulnerabilities.
Wrap-up
In summary, these emulations will evaluate security and incident response processes and support the improvement of your security control posture against the behaviors exhibited by FSB’s Center 16 activities. With data generated from continuous testing and use of these emulations, you can focus your teams on achieving key security outcomes, adjust your security controls, and work to elevate your total security program effectiveness against a known and dangerous threat. AttackIQ®, the leading provider of Adversarial Exposure Validation (AEV) solutions, is trusted by top organizations worldwide to validate security controls in real time. By emulating real-world adversary behavior, AttackIQ closes the gap between knowing about a vulnerability and understanding its true risk. AttackIQ’s AEV platform aligns with the Continuous Threat Exposure Management (CTEM) framework, enabling a structured, risk-based approach to ongoing security assessment and improvement. The company is committed to supporting its MSSP partners with a Flexible Preactive Partner Program that provides turn-key solutions, empowering them to elevate client security. AttackIQ is passionate about giving back to the cybersecurity community through its free award-winning AttackIQ Academy and founding research partnership with MITRE Center for Threat-Informed Defense.
