FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A

FSB Center 16 (Static Tundra / Berserk Bear) Exploits (TL-2026-1276), also tracked as AA26-194A, is a high-severity advanced persistent threat campaign scored CVSS 9.8, first published 2026-07-13. It is attributed to FSB Center 16 (Russia) with high confidence, affects Cisco IOS and IOS XE Software (Smart Install feature), references 1 CVE (CVE-2018-0171), maps to 22 MITRE ATT&CK techniques (T1016, T1040, T1046), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-1276

Threat ID
TL-2026-1276
Also known as
AA26-194A, Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
FSB Center 16
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
defense industrial base, communications, energy, financial services, government facilities, health, telecoms, manufacturing, higher education, critical infrastructure
Target regions
North America, Europe, Asia, Africa, ukraine
Detection rules
9
Indicators of compromise
16

Malware and tooling in FSB Center 16 (Static Tundra / Berserk Bear) Exploits

Malware and tooling: SYNful Knock - S0519, CISCO-CONFIG-COPY-MIB abuse tooling, GRE tunnel traffic interception

CISA, FBI, NSA, and an international coalition (CSE, ASD, NCSC-NZ, NCSC-UK, NUKIB, and agencies from the Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, and Sweden) issued joint advisory AA26-194A warning that Russian FSB Center 16 cyber actors — tracked as Static Tundra, Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, and Ghost Blizzard — are opportunistically scanning for and compromising poorly configured and end-of-life networking devices worldwide via default/weak SNMP community strings and unpatched Cisco Smart Install (CVE-2018-0171).

How FSB Center 16 (Static Tundra / Berserk Bear) Exploits works

On 2026-07-13, CISA and a broad international coalition of cybersecurity and intelligence agencies published AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting," documenting sustained, multi-year exploitation of Cisco networking devices by Russian Federal Security Service (FSB) Center 16 cyber actors. The activity cluster, publicly tracked by Cisco Talos as Static Tundra and assessed as a likely sub-cluster of the long-running Energetic Bear / Berserk Bear (aka Crouching Yeti, Dragonfly, Ghost Blizzard) operation, has been linked to FSB Center 16 by a 2022 US Department of Justice indictment.

The actors conduct broad, opportunistic internet scanning (leveraging services such as Shodan and Censys) to identify Cisco IOS and IOS XE devices running the legacy Smart Install (SMI) feature, which listens unauthenticated on TCP port 4786. Where Smart Install remains enabled, the actors exploit CVE-2018-0171 — a buffer overflow in SMI packet parsing (CWE-787/CWE-20) that Cisco patched in March 2018 but that persists on unpatched and end-of-life devices — to trigger device reloads or achieve arbitrary code execution. Post-exploitation, actors issue commands such as `tftp-server nvram:startup-config` to spawn a TFTP listener on the victim device and retrieve the running/startup configuration, harvesting locally stored credentials and SNMP community strings.

In parallel, actors conduct mass scanning for devices accepting default or weak SNMP community strings (commonly "public"/"private" with read-write access) using SNMPv1/v2c, then abuse the CISCO-CONFIG-COPY-MIB to remotely copy device configurations out via TFTP/FTP/RCP, in some cases spoofing source IP addresses to bypass ACL restrictions. Recovered configurations are mined for additional credentials, VPN/TACACS+ secrets, and network topology, enabling lateral movement to further devices.

On devices where deeper persistence is desired, the actors have been associated with the SYNful Knock firmware implant (first publicly documented in 2015) — a modular, reboot-persistent modification of the Cisco IOS image activated by a crafted "magic packet" TCP SYN sequence. Actors additionally create unauthorized privileged local user accounts, enable insecure legacy management services (e.g., re-enabling Telnet), modify ACLs to permit persistent inbound access, and in some environments establish GRE tunnels and collect NetFlow data to intercept and analyze victim network traffic for follow-on espionage collection.

Victimology spans Defense Industrial Base, communications, energy, financial services, government facilities, healthcare, telecommunications, manufacturing, and higher-education networks across North America, Europe, Asia, and Africa, with escalated and sustained targeting of Ukrainian organizations since Russia's February 2022 full-scale invasion. The group has also been associated with disruptive activity against European energy infrastructure, including reported involvement in an attack affecting Poland's energy grid in December 2025. Many of the exploited weaknesses (default/weak SNMP strings, enabled Smart Install, unencrypted legacy management protocols) are configuration issues rather than unpatched software, meaning organizations can substantially reduce exposure through router/switch hygiene alone, independent of vendor patch cycles.

MITRE ATT&CK techniques used in TL-2026-1276

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery

credential-access

T1040 Network Sniffing

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer

Credential Access

T1110 Brute Force; T1552 Unsecured Credentials

Persistence

T1136 Create Account; T1505 Server Software Component; T1556 Modify Authentication Process

Impact

T1498 Network Denial of Service

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

defense-impairment

T1599 Network Boundary Bridging; T1601 Modify System Image; T1685 Disable or Modify Tools

Collection

T1602 Data from Configuration Repository

Affected products and versions in FSB Center 16 (Static Tundra / Berserk Bear) Exploits

  • Cisco — IOS and IOS XE Software (Smart Install feature)
    Vulnerable versions: 15.2(5)e and other releases with Smart Install enabled prior to fix
    Fixed in: Cisco IOS/IOS XE releases per Cisco Bug ID CSCvg76186
  • Multiple — Networking devices with default/weak SNMP community strings (SNMPv1/v2c)
    Vulnerable versions: Any device configured with default or guessable read/write SNMP community strings
    Fixed in: Devices reconfigured with SNMPv3 and unique credentials

Remediation for FSB Center 16 (Static Tundra / Berserk Bear) Exploits

Patches

  • Cisco Bug ID CSCvg76186 — apply vendor-supplied fixed IOS/IOS XE release for CVE-2018-0171

Immediate actions

  • Disable the Cisco Smart Install feature on all IOS/IOS XE devices unless actively required (`no vstack` global config command)
  • Patch CVE-2018-0171 on all internet-reachable and internal Cisco IOS/IOS XE devices still running vulnerable versions
  • Replace default/weak SNMP community strings; disable SNMPv1/v2c and migrate to SNMPv3 with authentication and encryption
  • Audit device configurations for unauthorized local user accounts, modified ACLs, re-enabled Telnet, or unexpected TACACS+ changes
  • Restrict management-plane access (SNMP, SMI TCP/4786, Telnet, SSH) to trusted management networks via ACLs

Workarounds

  • Disable Smart Install via `no vstack` where patching is not immediately possible
  • Block inbound TCP/4786 (Smart Install Director port) at the network perimeter and internally

Longer-term hardening

  • Decommission or replace end-of-life networking devices no longer receiving vendor security patches
  • Deploy centralized configuration management and change-detection/integrity monitoring for network device configs
  • Implement network segmentation isolating management interfaces from general-purpose and internet-facing networks
  • Adopt Cyber Essentials / Cyber Assessment Framework style baselines for network device hardening
  • Enable logging/telemetry (NetFlow, syslog, AAA) from network devices to a centralized SIEM for anomaly detection

CVEs associated with FSB Center 16 (Static Tundra / Berserk Bear) Exploits

CVE-2018-0171

Weaknesses (CWE) in FSB Center 16 (Static Tundra / Berserk Bear) Exploits

CWE-787, CWE-20

Timeline of FSB Center 16 (Static Tundra / Berserk Bear) Exploits

  • SYNful Knock, a modular reboot-persistent Cisco IOS firmware implant later associated with this actor cluster, is first publicly documented by Mandiant/FireEye.
  • Cisco publishes a fix for CVE-2018-0171 (Smart Install buffer overflow, Bug ID CSCvg76186); many devices remain unpatched in production for years afterward.
  • Static Tundra/Berserk Bear begins aggressive, sustained exploitation of unpatched CVE-2018-0171 against internet-exposed Cisco devices.
  • Following Russia's full-scale invasion of Ukraine, actor targeting escalates against Ukrainian government, telecommunications, and critical-infrastructure networks.
  • Actor-controlled infrastructure IP 185.141.24[.]222 observed in exploitation/exfiltration activity.
  • Actor-controlled infrastructure IPs 185.141.24[.]28 and 185.82.200[.]181 begin an active-use window.
  • Actor-controlled infrastructure IP 185.82.202[.]34 begins an active-use window lasting through late February 2025.
  • Activity window for infrastructure IP 185.141.24[.]28 continues through this date, indicating sustained multi-year infrastructure reuse.
  • FBI/IC3 publish PSA 250820, "Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure," the precursor advisory to AA26-194A.
  • Static Tundra/FSB Center 16 actors reportedly associated with an attack affecting Poland's energy grid, alongside other Russian state-linked actors.
  • CISA, FBI, NSA, and an international coalition of partner agencies jointly publish AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting," consolidating TTPs and mitigation guidance.

Sources cited for FSB Center 16 (Static Tundra / Berserk Bear) Exploits

Threats related to FSB Center 16 (Static Tundra / Berserk Bear) Exploits

Detection coverage for TL-2026-1276

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1276 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1276

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats