FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A — Threadlinqs Intelligence
As of 2026-07-13, FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A is a high-severity apt threat attributed to FSB Center 16 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1276 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: APT
Attribution: FSB Center 16 · Russia · ESPIONAGE
CISA, FBI, NSA, and an international coalition (CSE, ASD, NCSC-NZ, NCSC-UK, NUKIB, and agencies from the Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, and Sweden) issued joint
On 2026-07-13, CISA and a broad international coalition of cybersecurity and intelligence agencies published AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting," documenting sustained, multi-year exploitation of Cisco networking devices by Russian Federal Security Service (FSB) Center 16 cyber actors. The activity cluster, publicly tracked by Cisco Talos as Static Tundra and assessed as a likely sub-cluster of the long-running Energetic Bear / Berserk Bear (aka Crouching Yeti, Dragonfly, Ghost Blizzard) operation, has been linked to FSB Center 16 by a 2022 US Department of Justice indictment.
The actors conduct broad, opportunistic internet scanning (leveraging services such as Shodan and Censys) to identify Cisco IOS and IOS XE devices running the legacy Smart Install (SMI) feature, which listens unauthenticated on TCP port 4786. Where Smart Install remains enabled, the actors exploit CVE-2018-0171 — a buffer overflow in SMI packet parsing (CWE-787/CWE-20) that Cisco patched in March 2018 but that persists on unpatched and end-of-life devices — to trigger device reloads or achieve arbitrary code execution. Post-exploitation, actors issue commands such as `tftp-server nvram:startup-config` to spawn a TFTP listener on the victim device and retrieve the running/startup configuration, harvesting locally stored credentials and SNMP community strings.
In parallel, actors conduct mass scanning for devices accepting default or weak SNMP community strings (commonly "public"/"private" with read-write access) using SNMPv1/v2c, then abuse the CISCO-CONFIG-COPY-MIB to remotely copy device configurations out via TFTP/FTP/RCP, in some cases spoofing source IP addresses to bypass ACL restrictions. Recovered configurations are mined for additional credentials, VPN/TACACS+ secrets, and network topology, enabling lateral movement to further devices.
On devices where deeper persistence is desired, the actors have been associated with the SYNful Knock firmware implant (first publicly documented in 2015) — a modular, reboot-persistent modification of the Cisco IOS image activated by a crafted "magic packet" TCP SYN sequence. Actors additionally create unauthorized privileged local user accounts, enable insecure legacy management services (e.g., re-enabling Telnet), modify ACLs to permit persistent inbound access, and in some environments establish GRE tunnels and collect NetFlow data to intercept and analyze victim network traffic for follow-on espionage collection.
Victimology spans Defense Industrial Base, communications, energy, financial services, government facilities, healthcare, telecommunications, manufacturing, and higher-education networks across North America, Europe, Asia, and Africa, with escalated and sustained targeting of Ukrainian organizations since Russia's February 2022 full-scale invasion. The group has also been associated with disruptive activity against European energy infrastructure, including reported involvement in an attack affecting Poland's energy grid in December 2025. Many of the exploited weaknesses (default/weak SNMP strings, enabled Smart Install, unencrypted legacy management protocols) are configuration issues rather than unpatched software, meaning organizations can substantially reduce exposure through router/switch hygiene alone, independent of vendor patch cycles.
Weaknesses (CWE)
CWE-787, CWE-20
Target sectors: defense industrial base, communications, energy, financial services, government facilities, health, telecoms, manufacturing, higher education, critical infrastructure
Target regions: North America, Europe, Asia, Africa, ukraine
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, CVE-2018-0171, T1590, T1595, T1583, T1190, T1078, T1059, T1136, T1556, T1505, T1601