US Government Warns Russian State Hackers Target Home and Office Routers
Russian state-sponsored hacking groups backed by the FSB continue to mass-compromise home and small office routers worldwide, according to a new advisory from the Cybersecurity and Infrastructure Security Agency. The hackers exploit poorly configured devices, particularly those with exposed SNMP agents that still accept default or common credentials. Once compromised, the routers become part of large botnets that serve as proxy networks for launching attacks against critical infrastructure and sensitive organizations.
The advisory, co-issued by cybersecurity agencies from the United States, Australia, Denmark, New Zealand, and the United Kingdom, identifies the threat actors under multiple tracking names including Berserk Bear, Energetic Bear, Dragonfly, and others. These groups scan IP ranges for vulnerable networking devices and use automated botnets to enroll them into their operations. Disruption efforts by the US government, Google, and other companies have struggled to keep pace, as hackers quickly rebuild their botnets whenever previous ones are dismantled.
CISA urges router owners to take immediate protective steps, including changing all default passwords, disabling SNMP if it is not needed, and ensuring firmware remains up to date. The agency emphasizes that residential routers serve as a critical first line of defense and that securing them protects not only individual users but also the broader networks and organizations that hackers ultimately target through these compromised devices.