# FSB Center 16

> As of 2026-07-14, FSB Center 16 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning vulnerability, threat intel, apt. Also known as Static Tundra. ATT&CK coverage spans 112 techniques across 24 tactics in 6 of 6 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1046 (Network Service Discovery), T1190 (Exploit Public-Facing Application).

- **Nation:** Russia
- **Tracked threats:** 6
- **Categories:** VULNERABILITY, THREAT_INTEL, APT, ICS_SCADA, CAMPAIGN
- **Also known as:** Static Tundra
- **As of:** 2026-07-14

## ATT&CK techniques observed

112 techniques observed across 6 of 6 tracked threats. Tactics: Impact (14), Collection (9), Credential Access (9), Discovery (9), Persistence (8), Command and Control (7).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 6 of 6 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 5 of 6 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 5 of 6 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 5 of 6 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 4 of 6 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 6 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 4 of 6 tracked threats
- [T1136](https://intel.threadlinqs.com/technique/T1136) Create Account — Persistence — observed in 4 of 6 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 4 of 6 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 4 of 6 tracked threats
- [T1595](https://intel.threadlinqs.com/technique/T1595) Active Scanning — Reconnaissance — observed in 4 of 6 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 3 of 6 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 6 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 6 tracked threats
- [T1040](https://intel.threadlinqs.com/technique/T1040) Network Sniffing — Credential Access — observed in 3 of 6 tracked threats

## Tracked threats

- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers](https://intel.threadlinqs.com/threat/TL-2026-1312) — CRITICAL
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)](https://intel.threadlinqs.com/threat/TL-2026-1290) — MEDIUM
- [FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A](https://intel.threadlinqs.com/threat/TL-2026-1276) — HIGH
- [Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms](https://intel.threadlinqs.com/threat/TL-2026-0037) — CRITICAL
- [Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper](https://intel.threadlinqs.com/threat/TL-2026-0014) — CRITICAL
- [Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0004) — CRITICAL

## Related CVEs

3 CVEs referenced by tracked FSB Center 16 activity.

- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/FSB%20Center%2016
