US and Allies Warn of Russian Hackers Targeting Critical Infrastructure Routers

Cybersecurity agencies from the United States and eight allied nations issue a joint advisory warning that Russian state hackers are actively targeting critical infrastructure networks. The advisory, co-authored by the NSA, FBI, and CISA alongside agencies from Australia, the UK, Canada, and several European nations, attributes the campaign to the Russian Federal Security Service's Center 16. This persistent threat group scans for vulnerable routers using default or weak SNMP credentials to gain initial access.

The hackers exploit poorly configured routers and known vulnerabilities in Cisco devices, including the Smart Install feature flaw tracked as CVE-2018-0171. Once they compromise a router, they copy configuration files and exfiltrate them to attacker-controlled servers using the Trivial File Transfer Protocol. Sectors most at risk include energy, healthcare, financial services, defense, communications, and government services, making the threat particularly concerning for national security.

The advisory recommends several mitigation measures for network defenders, including upgrading to SNMPv3, disabling Cisco Smart Install, and enforcing strong unique passwords across all devices. Agencies also urge organizations to block TFTP and SNMP traffic at edge firewalls, keep software and firmware updated, and replace any end-of-life equipment. These steps significantly reduce the attack surface and help protect critical systems from this ongoing Russian cyber campaign.

Read More at the original source →