Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-02

FSB Center 16

Also known as:Static Tundra

As of 2026-07-14, FSB Center 16 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning vulnerability, threat intel, apt. Also known as Static Tundra. ATT&CK coverage spans 112 techniques across 24 tactics in 6 of 6 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1046 (Network Service Discovery), T1190 (Exploit Public-Facing Application).

Tracked threats
64 critical · 1 high · 1 medium
First seen
2026-02-02
Last seen
2026-07-14
ATT&CK techniques
112across 6 of 6 threats
Related CVEs
3Referenced by its activity
Attribution
RussiaNation or origin
Nation: Russia · 6 tracked threat(s) · Categories: VULNERABILITY, THREAT_INTEL, APT, ICS_SCADA, CAMPAIGN

Activity timeline

FSB Center 16 appears in 6 tracked threats between and ; the busiest month was 2026-02 with 3 reports.

ATT&CK techniques observed

112 techniques observed across 6 of 6 tracked threats · Impact (14), Collection (9), Credential Access (9), Discovery (9), Persistence (8), Command and Control (7)
  • T1059 Command and Scripting Interpreter — Executionobserved in 6 of 6 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 5 of 6 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 5 of 6 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 5 of 6 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 4 of 6 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 6 tracked threats
  • T1110 Brute Force — Credential Accessobserved in 4 of 6 tracked threats
  • T1136 Create Account — Persistenceobserved in 4 of 6 tracked threats
  • T1485 Data Destruction — Impactobserved in 4 of 6 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 4 of 6 tracked threats
  • T1595 Active Scanning — Reconnaissanceobserved in 4 of 6 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 3 of 6 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 6 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
  • T1040 Network Sniffing — Credential Accessobserved in 3 of 6 tracked threats

Tracked threats

Related CVEs

3 CVEs referenced by tracked FSB Center 16 activity