FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack — Threadlinqs Intelligence
As of 2026-07-13, FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack is a high-severity nation state threat attributed to FSB Centre 16 (Berserk Bear (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1283 · Severity: HIGH · CVSS: 9.8 · Status: ACTIVE · Category: NATION_STATE
Attribution: FSB Centre 16 (Berserk Bear · Russia · ESPIONAGE
The UK NCSC and 18 partner agencies across 12 countries issued a joint advisory attributing sustained targeting of critical infrastructure network devices to Russia's FSB Centre 16 (Berserk Bear /
Centre 16 of Russia's Federal Security Service (FSB) — publicly tracked under the aliases Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and (per Cisco Talos) Static Tundra — is a long-running (10+ year) Russian state-sponsored cyber espionage operation specializing in the compromise of network infrastructure devices to gain durable footholds inside organizations of strategic interest to the Russian government. On 13 July 2026 the UK National Cyber Security Centre (NCSC), joined by 18 partner agencies across 12 countries (Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, Sweden, and the United States), published a joint advisory warning that the group is actively targeting the communications, defence, energy, financial services, government, and healthcare sectors.
The actor's primary access technique is internet-wide scanning for routers and switches still configured with default or weak SNMP (Simple Network Management Protocol) community strings and passwords, most commonly SNMPv1/v2 configurations lacking authentication or encryption. Where SNMP access alone is insufficient, the actor pivots to exploiting well-documented Cisco device vulnerabilities, most notably CVE-2018-0171, a CVSS 9.8 critical flaw in the Cisco IOS/IOS XE Smart Install (SMI) feature that allows an unauthenticated remote attacker to send crafted Smart Install messages to TCP port 4786 to trigger a device reload, cause an indefinite loop, or achieve arbitrary code execution due to inadequate packet validation (CWE-787 out-of-bounds write / CWE-20 improper input validation). Cisco patched CVE-2018-0171 in March 2018 and it has been on the CISA Known Exploited Vulnerabilities (KEV) catalog since November 2021, yet Static Tundra continues to find and compromise unpatched, end-of-life devices with Smart Install still enabled. The group additionally abuses unspecified Cisco web-management-portal vulnerabilities to gain device control.
Once a device is compromised, the actor's exploitation chain enables a TFTP server on the target and retrieves the running/startup configuration, harvesting SNMP community strings, local credentials, and network topology data. Persistence is established through compromised/newly-created privileged local accounts, additional read-write SNMP community strings, modification of TACACS+ configuration and ACLs to evade detection, and — per Talos's historical tracking — the SYNful Knock modular Cisco IOS firmware implant (first publicly documented in 2015), which survives reboots and grants remote access via a crafted 'magic packet' TCP SYN. The actor uses spoofed source IP addresses during SNMP command execution to complicate attribution and evade network monitoring, performs internal discovery via native device commands (e.g. 'show cdp neighbors') and by consuming Shodan/Censys scan data, establishes GRE tunnels and captures NetFlow data for traffic collection, and exfiltrates configuration data over TFTP, FTP, RCP, and the Cisco CISCO-CONFIG-COPY-MIB.
On 29 December 2025, a coordinated destructive cyber campaign hit at least thirty Polish wind and photovoltaic generation sites, a major combined heat and power (CHP) plant, and a manufacturing company. Per CERT Polska's incident report, the intrusion combined a long period of infiltration, theft of sensitive data, compromise of privileged Active Directory accounts, and unrestricted lateral movement, culminating in deployment of a previously undocumented wiper — DynoWiper (also identified as Win32/KillFiles.NMO) — intended to irreversibly destroy data on internal-network devices. Initial access to the OT/ICS environment was gained through vulnerable internet-facing edge devices. The attackers reached and damaged Hitachi RTU 560 remote terminal units, Mikronika controllers, ABB Relion 650 protection IEDs, Moxa NPort serial servers, and Windows-based HMIs and domain controllers. At the renewable-energy sites the a
Weaknesses (CWE)
CWE-787, CWE-20
Target sectors: energy, government administration, defence, communications, financial services, health, telecoms, higher education, manufacturing, critical infrastructure
Target regions: Europe, poland, ukraine, united kingdom, North America, Asia, Africa
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
NATION_STATE, HIGH, threat intelligence, cybersecurity, CVE-2018-0171, T1595.001, T1590, T1583.003, T1587.001, T1190, T1078.001, T1133, T1059, T1601.001, T1136.001