Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory
Russian FSB Center 16 (Static Tundra/Berserk Bear) (TL-2026-1277), also tracked as Static Tundra Cisco Smart Install Campaign, is a high-severity software vulnerability scored CVSS 9.8, first published 2026-07-13 and last reviewed 2026-07-19. It is attributed to Static Tundra (Russia) with high confidence, affects Cisco IOS Software, references 2 CVEs (CVE-2018-0171, CVE-2008-4128), maps to 34 MITRE ATT&CK techniques (T1003, T1018, T1027), and is covered by 9 detection rules and 37 indicators of compromise.
Key facts for TL-2026-1277
- Threat ID
- TL-2026-1277
- Also known as
- Static Tundra Cisco Smart Install Campaign, FSB Center 16 Network Device Espionage
- Severity
- HIGH
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-13
- Last reviewed
- 2026-07-19
- Attribution
- Static Tundra
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- defense industrial base, communications, energy, financial services, government administration, health, telecoms, higher education, manufacturing
- Target regions
- North America, Europe, Asia, Africa, ukraine
- Detection rules
- 9
- Indicators of compromise
- 37
- Updates
- 2026-07-19 · revalidated 1× · latest source
Malware and tooling in Russian FSB Center 16 (Static Tundra/Berserk Bear)
Malware and tooling: SYNful Knock - S0519, Censys, Shodan
NSA, FBI, and 12 co-signing nations issued a joint cybersecurity advisory (IC3 CSA-260713) warning that Russia's FSB Center 16 — tracked as Static Tundra, Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, and Ghost Blizzard — has for over a decade scanned the internet for and exploited unpatched Cisco networking devices via the Smart Install feature (CVE-2018-0171) and legacy SNMP/HTTP flaws (CVE-2008-4128), harvesting device configurations en masse across defense, communications, energy, financial services, government, and healthcare sectors.
How Russian FSB Center 16 (Static Tundra/Berserk Bear) works
Static Tundra, assessed with high confidence as a sub-cluster of the FSB Center 16-linked Energetic Bear/Berserk Bear/Dragonfly cluster, has run a persistent global espionage campaign since at least 2015 against network infrastructure. The group's core objective is to compromise routers and switches to extract device configuration files en masse, banking that access for later use aligned with Russian state strategic interests. Its primary vector is CVE-2018-0171, a critical (CVSS 9.8) unauthenticated remote code execution / denial-of-service flaw in the Smart Install feature of Cisco IOS and IOS XE software: a crafted Smart Install message sent to TCP port 4786 triggers a buffer overflow that can reload the device, cause a watchdog crash, or grant arbitrary code execution. Cisco disclosed and patched this flaw in March 2018; despite a fixed release existing for over seven years, thousands of internet-facing, end-of-life devices remain vulnerable because Smart Install is enabled by default and organizations have not upgraded or disabled it (`no vstack`). Static Tundra combines this with CVE-2008-4128, a set of decade-old CSRF flaws in the Cisco IOS 12.4 HTTP administration interface on 871 ISRs, and with abuse of legacy unencrypted management protocols — SNMPv1/v2c with default or compromised read-write community strings (`public`, `anonymous`) and unauthenticated HTTP — to gain a secondary access path into devices that were never intended to be internet-reachable. Once inside a device, the actor spawns a TFTP server via `tftp-server nvram:startup-config`, connects to it to pull the startup configuration, and mines the extracted config for embedded credentials and SNMP community strings, which are then reused to pivot to adjacent devices. Persistence techniques include creating privileged (level 15) local accounts, modifying SNMP read-write strings, and — per historical FBI/Cisco reporting on this actor cluster — deploying the SYNful Knock firmware implant, a modular malicious IOS image modification that survives reboots and is activated via crafted 'magic packet' traffic. To move data and evade detection, the actor establishes GRE tunnels that redirect victim NetFlow/traffic to attacker-controlled infrastructure, exfiltrates configuration files outbound via TFTP/FTP (`copy running-config ftp://user:pass@host/output.txt`), spoofs source addresses on SNMP traffic to bypass ACLs, and modifies TACACS+ configuration to suppress remote logging of its activity. Target reconnaissance leverages native device commands (`show cdp neighbors`) plus internet-wide scan data from services like Shodan and Censys to identify vulnerable Smart-Install-enabled hosts at scale. The FBI and Cisco Talos both issued standalone warnings on this campaign in August 2025 after observing the actors collect configuration files for thousands of US-linked networking devices over the prior year, and in December 2025 the same cluster was linked to an attack on Poland's energy grid. The July 13, 2026 joint advisory — co-signed by the US, Canada, Australia, New Zealand, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, Sweden, and the UK — confirms the campaign is ongoing, has escalated against Ukraine and allied nations since the 2022 invasion, and now spans telecommunications, higher education, manufacturing, defense industrial base, energy, financial services, government facilities, and healthcare targets across North America, Europe, Asia, and Africa. Mitigation is straightforward but requires action: patch or retire affected IOS/IOS XE devices, disable Smart Install entirely, replace SNMPv1/v2c with SNMPv3, disable Telnet/HTTP management in favor of SSH/HTTPS, enforce strong Type 8/Type 6 password hashing, and treat device configurations as untrusted (verify against a centralized, version-controlled source of truth rather than the device itself).
MITRE ATT&CK techniques used in TL-2026-1277
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files
Discovery
T1018 Remote System Discovery; T1040 Network Sniffing; T1046 Network Service Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1070.007 Indicator Removal: Clear Network Connection History and Configurations; T1205 Traffic Signaling
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Execution
T1059 Command and Scripting Interpreter; T1059.008 Network Device CLI
Persistence
T1078.003 Valid Accounts: Local Accounts; T1098 Account Manipulation; T1136 Create Account; T1136.001 Create Account: Local Account
Command and Control
T1090 Proxy; T1095 Non-Application Layer Protocol; T1572 Protocol Tunneling
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1498 Network Denial of Service
Reconnaissance
T1590 Gather Victim Network Information; T1595.001 Active Scanning: Scanning IP Blocks; T1595.002 Active Scanning: Vulnerability Scanning; T1596 Search Open Technical Databases
defense-impairment
T1601 Modify System Image; T1686 Disable or Modify System Firewall
Collection
T1602 Data from Configuration Repository; T1602.001 Data from Configuration Repository: SNMP (MIB Dump); T1602.002 Data from Configuration Repository: Network Device Configuration Dump
Affected products and versions in Russian FSB Center 16 (Static Tundra/Berserk Bear)
- Cisco — IOS Software
Vulnerable versions: releases with Smart Install enabled prior to fixed train per cisco-sa-20180328-smi2
Fixed in: Cisco-recommended fixed IOS releases per cisco-sa-20180328-smi2 - Cisco — IOS XE Software
Vulnerable versions: releases with Smart Install enabled prior to fixed train per cisco-sa-20180328-smi2
Fixed in: Cisco-recommended fixed IOS XE releases per cisco-sa-20180328-smi2 - Cisco — 871 Integrated Services Router (IOS 12.4 HTTP Administration)
Vulnerable versions: IOS 12.4 on Cisco 871 ISR
Fixed in: Vendor-patched IOS 12.4 releases addressing CVE-2008-4128
Remediation for Russian FSB Center 16 (Static Tundra/Berserk Bear)
Patches
- Apply Cisco's fixed IOS/IOS XE releases for CVE-2018-0171 per cisco-sa-20180328-smi2
- Apply vendor guidance for CVE-2008-4128 on affected 871 ISR / IOS 12.4 HTTP administration builds
Immediate actions
- Disable the Cisco Smart Install feature globally with 'no vstack' on all IOS/IOS XE devices
- Block or restrict TCP/4786 (Smart Install) at network boundaries and on management interfaces
- Rotate all SNMP community strings and disable SNMPv1/v2c in favor of SNMPv3 with authPriv
- Audit running/startup configs on internet-reachable Cisco devices for unauthorized privilege-15 accounts, TFTP-server directives, or modified ACLs/TACACS+ settings
Workarounds
- Disable Smart Install client functionality if patching is not immediately possible
- Restrict management-plane access (SNMP, HTTP, Telnet, Smart Install) to trusted management VLANs/ACLs only
- Disable Telnet and unauthenticated HTTP management; use SSH and HTTPS exclusively
Longer-term hardening
- Replace or upgrade end-of-life Cisco IOS/IOS XE hardware that cannot receive the CVE-2018-0171 patch
- Centralize network device configuration management and treat on-device config as untrusted, not a source of truth
- Enforce MFA and AAA-based access control for all network device administrative interfaces
- Deploy NetFlow/syslog monitoring with alerting on new GRE tunnels, loopback interfaces, and logging gaps
CVEs associated with Russian FSB Center 16 (Static Tundra/Berserk Bear)
Weaknesses (CWE) in Russian FSB Center 16 (Static Tundra/Berserk Bear)
CWE-120, CWE-352, CWE-287, CWE-284, CWE-798
Timeline of Russian FSB Center 16 (Static Tundra/Berserk Bear)
- CVE-2008-4128 CSRF vulnerabilities disclosed in Cisco IOS 12.4 HTTP administration on the 871 ISR
- FSB Center 16 (Static Tundra sub-cluster of Berserk Bear/Energetic Bear/Dragonfly) begins large-scale scanning and compromise of network devices accepting legacy unencrypted management protocols
- Cisco IOS 12.4 Mainline reaches end-of-support, leaving CVE-2008-4128-affected devices permanently unpatched.
- Cisco discloses and patches CVE-2018-0171, a critical (CVSS 9.8) unauthenticated RCE/DoS flaw in the Smart Install feature of IOS and IOS XE
- FBI observes Static Tundra begin aggressive, sustained exploitation of CVE-2018-0171 against internet-facing Cisco devices, a marked escalation from earlier opportunistic activity
- Static Tundra escalates targeting of Ukraine and allied nations following the Russian invasion of Ukraine
- US DOJ unseals indictment against FSB Center 16 officers (including Pavel Aleksandrovich Akulov) tied to the Energetic Bear/Berserk Bear/Dragonfly cluster for critical-infrastructure intrusion campaigns, formally linking the cluster to FSB Center 16
- Cyber Security Agency of Singapore issues alert (AL-2025-083) on active exploitation of the Cisco Smart Install client vulnerability.
- FBI and Cisco Talos independently publish advisories confirming active, ongoing exploitation of CVE-2018-0171 by Static Tundra, noting configuration files collected for thousands of US-linked devices over the prior year
- An attack on Poland's energy grid is attributed to FSB Center 16 / Static Tundra
- CISA adds CVE-2008-4128 to the Known Exploited Vulnerabilities catalog after confirming active exploitation evidence.
- CISA publishes joint advisory AA26-194A, 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,' co-signed by NSA, FBI, DC3, and partner agencies from 12 additional countries (19 agencies total).
- NSA, FBI, and 12 additional co-signing nations release joint cybersecurity advisory (IC3 CSA-260713) confirming the decade-long campaign remains active against critical infrastructure worldwide
- Forbes and other outlets report FBI warning on FSB Center 16 (Military Unit 71330) router-targeting campaign, spanning at least 16 years of documented Center 16 cyber operations.
- Splunk publishes detection guide mapping Static Tundra's CVE-2018-0171 exploitation to Snort signatures and Splunk detection logic.
- IC3 publishes companion joint Cybersecurity Advisory 2026/260713 (PDF) detailing the campaign and mitigations.
Update history for TL-2026-1277
- 2026-07-19 — US and Allied Governments Warn of Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploitation of Legacy Network Device Weaknesses (CVE-2018-0171, CVE-2008-4128): What changed No severity/exploitability/status/CVSS escalation — both reports rate this HIGH/ACTIVE/9.8. The update instead broadens attribution and formalizes the advisory record: CISA published companion advisory AA26-194A (19 agencies, 1
Sources cited for Russian FSB Center 16 (Static Tundra/Berserk Bear)
- Joint warning from 13 nations regarding Russian state-sponsored cyber targeting of critical infrastructure
- IC3 Joint Cybersecurity Advisory CSA-260713
- CVE-2018-0171 Detail
- CVE-2008-4128 Detail
- Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
- Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
- Static Tundra Analysis & CVE-2018-0171 Detection Guide
- FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage
- Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw
- Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI
- Russian state cyber group Static Tundra exploiting Cisco devices, FBI warns
- US and allies warn of Russian critical infrastructure attacks
- UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
- Splunk Security Content: Cisco Secure Firewall - Static Tundra Smart Install Abuse
Threats related to Russian FSB Center 16 (Static Tundra/Berserk Bear)
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers
- Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A
Detection coverage for TL-2026-1277
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1277 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1277
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.