FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers

FSB Center 16 (Static Tundra) Exploits SNMP Config (TL-2026-1312), also tracked as Berserk Bear, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-14. It is attributed to FSB Center 16 (Russia) with high confidence, affects Cisco IOS / IOS XE Software (Smart Install client feature), references 2 CVEs (CVE-2018-0171, CVE-2008-4128), maps to 31 MITRE ATT&CK techniques (T1016, T1021, T1040), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1312

Threat ID
TL-2026-1312
Also known as
Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-14
Attribution
FSB Center 16
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
telecoms, higher education, manufacturing, energy, defense, financial services, government administration, health, critical infrastructure
Target regions
North America, Europe, Asia, Africa, ukraine, poland, united states of america
Detection rules
9
Indicators of compromise
30

Russia's FSB Center 16, tracked as Static Tundra (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard), abuses weak/default SNMP community strings to exfiltrate Cisco router configs via TFTP and exploits the unauthenticated Cisco Smart Install buffer overflow (CVE-2018-0171) for RCE. Campaign spans a decade of critical-infrastructure targeting, incl. exploitation of CVE-2018-0171 by Salt Typhoon (Feb 2025) and a December 2025 attack on Poland's power grid formally attributed by UK/EU on 2026-07-13.

How FSB Center 16 (Static Tundra) Exploits SNMP Config works

Static Tundra is a Russian state-sponsored cyber espionage group operated by FSB Center 16 (Military Unit 71330), publicly documented by Cisco Talos in August 2025 and jointly attributed by CISA, NSA, FBI, and international partners in advisory AA26-194A (July 13, 2026). Talos assesses with high confidence that Static Tundra is a sub-cluster of the long-running 'Energetic Bear'/'Berserk Bear' activity cluster, historically tracked by industry as Dragonfly, Crouching Yeti, and (by Microsoft) Ghost Blizzard, and with moderate confidence links the group to the 2015-era SYNful Knock firmware implant.

The group's signature technique combines two legitimate Cisco management functions turned malicious: (1) abusing weak or default SNMP community strings to issue SNMP Set-Requests against the CISCO-CONFIG-COPY-MIB (OID 1.3.6.1.4.1.9.9.96), instructing a router to copy its own running-config to an attacker-controlled TFTP server, harvesting embedded local credentials and additional SNMP strings for lateral movement; and (2) exploiting CVE-2018-0171, an unauthenticated buffer overflow in the Cisco IOS/IOS XE Smart Install feature (TCP/4786, patched March 2018 via cisco-sa-20180328-smi2, CVSS 9.8), against unpatched or end-of-life switches to gain arbitrary code execution or force reload/DoS. Post-compromise, operators create local accounts, enable Telnet, weaken TACACS+ logging, and build GRE tunnels to redirect and collect NetFlow/traffic of interest, and in some cases deployed the SYNful Knock IOS image implant for persistence across reboots.

Targeting has spanned telecommunications, higher education, manufacturing, energy, defense, financial services, government, and healthcare across North America, Asia, Africa, and Europe, with escalated operations against Ukrainian entities since 2022. The decade-old CVE-2018-0171 flaw was independently confirmed by Cisco Talos to have also been exploited by Salt Typhoon (China-linked) in February 2025, underscoring how unpatched legacy Cisco infrastructure remains a shared attack surface across multiple nation-state actors. On 29 December 2025, coordinated destructive attacks struck more than 30 Polish wind/solar farms and a combined heat-and-power plant serving roughly half a million customers; CERT Polska found infrastructure overlap with Static Tundra/Berserk Bear/Dragonfly, and UK and EU governments formally attributed the intrusion to Static Tundra/FSB Center 16 with high confidence on 2026-07-13 (though ESET and Dragos separately assessed the destructive wiper component with moderate confidence to Sandworm). CISA added the related legacy flaw CVE-2008-4128 (Cisco IOS 12.4 CSRF in the HTTP administration interface, CWE-352) to its Known Exploited Vulnerabilities catalog on 2026-07-13, the same day AA26-194A was published, with a federal remediation deadline of 2026-07-16 under BOD 22-01.

MITRE ATT&CK techniques used in TL-2026-1312

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services

Credential Access

T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Defense Evasion

T1070 Indicator Removal

Command and Control

T1090 Proxy; T1572 Protocol Tunneling

Collection

T1119 Automated Collection; T1602 Data from Configuration Repository

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1136 Create Account

Impact

T1485 Data Destruction; T1498 Network Denial of Service; T1529 System Shutdown/Reboot

Resource Development

T1583 Acquire Infrastructure

resource-development

T1584 Compromise Infrastructure

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

defense-impairment

T1600 Weaken Encryption; T1601 Modify System Image; T1685 Disable or Modify Tools

Affected products and versions in FSB Center 16 (Static Tundra) Exploits SNMP Config

  • Cisco — IOS / IOS XE Software (Smart Install client feature)
    Vulnerable versions: Releases with Smart Install client enabled, pre-March 2018 fix
    Fixed in: Fixed releases per cisco-sa-20180328-smi2 bundled publication (March 28, 2018)
  • Cisco — IOS 12.4 HTTP Administration interface
    Vulnerable versions: Cisco IOS 12.4 (e.g., Cisco 871 Integrated Services Routers)
    Fixed in: Not applicable for EoL devices; upgrade/replace recommended

Remediation for FSB Center 16 (Static Tundra) Exploits SNMP Config

Patches

  • Cisco IOS/IOS XE fixed releases per cisco-sa-20180328-smi2 (CVE-2018-0171, released March 28, 2018)
  • Cisco IOS 12.4 mitigations/upgrades for CVE-2008-4128 (added to CISA KEV 2026-07-13)

Immediate actions

  • Disable Cisco Smart Install client feature on all switches unless actively required
  • Block TCP/4786 (Smart Install) at network and host firewalls
  • Disable SNMPv1/SNMPv2 and migrate to SNMPv3 with strong authentication/encryption
  • Rotate and enforce strong, unique SNMP community strings; remove default strings
  • Block or restrict TFTP at the network perimeter and internally where not operationally required
  • Restrict internet-reachable device management interfaces (SNMP, Telnet, HTTP admin) to trusted management networks
  • Audit routers/switches for unauthorized local accounts, GRE tunnels, and modified ACL/logging configuration

Workarounds

  • Disable Smart Install client: no vstack (Cisco IOS)
  • Apply infrastructure ACLs blocking TCP/4786 and TFTP (UDP/69) from untrusted sources
  • Disable SNMP write access and CISCO-CONFIG-COPY-MIB where not needed

Longer-term hardening

  • Replace or upgrade end-of-life Cisco devices that cannot receive patches
  • Implement network segmentation isolating management planes from general traffic
  • Deploy centralized AAA (TACACS+/RADIUS) with strong password-storage types and monitor for tampering
  • Establish continuous asset inventory and external attack-surface monitoring (Shodan/Censys-style exposure) for management protocols
  • Adopt configuration integrity monitoring/backups with alerting on unexpected config-copy operations

CVEs associated with FSB Center 16 (Static Tundra) Exploits SNMP Config

CVE-2018-0171, CVE-2008-4128

Weaknesses (CWE) in FSB Center 16 (Static Tundra) Exploits SNMP Config

CWE-120, CWE-787, CWE-352, CWE-284, CWE-306

Timeline of FSB Center 16 (Static Tundra) Exploits SNMP Config

  • CVE-2008-4128, a CSRF vulnerability in the Cisco IOS 12.4 HTTP Administration interface, is publicly disclosed.
  • Dragonfly/Energetic Bear begins the 'Havex' phase, a supply-chain campaign compromising ICS/SCADA vendors and infecting more than 17,000 devices, including power and energy company controllers.
  • Dragonfly 2.0 phase begins, directly targeting energy sector entities, ICS/SCADA engineers, and U.S. government agencies including the Nuclear Regulatory Commission.
  • Cisco publicly reports the SYNful Knock Cisco IOS firmware implant; Talos later links it with moderate confidence to Static Tundra activity.
  • Cisco publishes advisory cisco-sa-20180328-smi2 and patches CVE-2018-0171, an unauthenticated Smart Install buffer overflow (CVSS 9.8) affecting an estimated 250,000 vulnerable devices.
  • A federal grand jury in Kansas indicts three FSB Center 16 (Military Unit 71330) officers for hacking campaigns targeting critical infrastructure.
  • Static Tundra escalates operations against Ukrainian entities following Russia's full-scale invasion of Ukraine.
  • DOJ publicly unseals indictments against four Russian government employees for the Havex/Dragonfly and Triton/Trisis critical-infrastructure hacking campaigns.
  • Cisco Talos confirms China-linked Salt Typhoon independently exploiting the same CVE-2018-0171 Smart Install flaw.
  • Cisco Talos publishes the 'Static Tundra' report attributing years of Cisco device exploitation to FSB Center 16; FBI and IC3 issue coordinated alerts (PSA250820).
  • Coordinated destructive cyberattacks hit more than 30 Polish wind and solar farms and a combined heat-and-power plant serving ~500,000 customers, involving firmware damage, file deletion, and wiper malware deployment.
  • CERT Polska publishes an incident report finding infrastructure overlap between the December 2025 grid attack and Static Tundra/Berserk Bear/Dragonfly; ESET and Dragos separately assess wiper activity to Sandworm with moderate confidence.
  • CISA, NSA, FBI and international partners publish the joint Cybersecurity Advisory 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting.'
  • CISA publishes advisory AA26-194A and adds CVE-2008-4128 to the Known Exploited Vulnerabilities catalog, with a federal remediation deadline of 2026-07-16 under BOD 22-01.
  • UK and EU governments formally attribute the December 2025 Poland power grid attack to Static Tundra/FSB Center 16 with high confidence.

Sources cited for FSB Center 16 (Static Tundra) Exploits SNMP Config

Threats related to FSB Center 16 (Static Tundra) Exploits SNMP Config

Detection coverage for TL-2026-1312

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1312 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1312

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats