FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers — Threadlinqs Intelligence
As of 2026-07-14, FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers is a critical-severity vulnerability threat attributed to FSB Center 16 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1312 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: FSB Center 16 · Russia · ESPIONAGE
Russia's FSB Center 16, tracked as Static Tundra (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard), abuses weak/default SNMP community strings to exfiltrate Cisco router
Static Tundra is a Russian state-sponsored cyber espionage group operated by FSB Center 16 (Military Unit 71330), publicly documented by Cisco Talos in August 2025 and jointly attributed by CISA, NSA, FBI, and international partners in advisory AA26-194A (July 13, 2026). Talos assesses with high confidence that Static Tundra is a sub-cluster of the long-running 'Energetic Bear'/'Berserk Bear' activity cluster, historically tracked by industry as Dragonfly, Crouching Yeti, and (by Microsoft) Ghost Blizzard, and with moderate confidence links the group to the 2015-era SYNful Knock firmware implant.
The group's signature technique combines two legitimate Cisco management functions turned malicious: (1) abusing weak or default SNMP community strings to issue SNMP Set-Requests against the CISCO-CONFIG-COPY-MIB (OID 1.3.6.1.4.1.9.9.96), instructing a router to copy its own running-config to an attacker-controlled TFTP server, harvesting embedded local credentials and additional SNMP strings for lateral movement; and (2) exploiting CVE-2018-0171, an unauthenticated buffer overflow in the Cisco IOS/IOS XE Smart Install feature (TCP/4786, patched March 2018 via cisco-sa-20180328-smi2, CVSS 9.8), against unpatched or end-of-life switches to gain arbitrary code execution or force reload/DoS. Post-compromise, operators create local accounts, enable Telnet, weaken TACACS+ logging, and build GRE tunnels to redirect and collect NetFlow/traffic of interest, and in some cases deployed the SYNful Knock IOS image implant for persistence across reboots.
Targeting has spanned telecommunications, higher education, manufacturing, energy, defense, financial services, government, and healthcare across North America, Asia, Africa, and Europe, with escalated operations against Ukrainian entities since 2022. The decade-old CVE-2018-0171 flaw was independently confirmed by Cisco Talos to have also been exploited by Salt Typhoon (China-linked) in February 2025, underscoring how unpatched legacy Cisco infrastructure remains a shared attack surface across multiple nation-state actors. On 29 December 2025, coordinated destructive attacks struck more than 30 Polish wind/solar farms and a combined heat-and-power plant serving roughly half a million customers; CERT Polska found infrastructure overlap with Static Tundra/Berserk Bear/Dragonfly, and UK and EU governments formally attributed the intrusion to Static Tundra/FSB Center 16 with high confidence on 2026-07-13 (though ESET and Dragos separately assessed the destructive wiper component with moderate confidence to Sandworm). CISA added the related legacy flaw CVE-2008-4128 (Cisco IOS 12.4 CSRF in the HTTP administration interface, CWE-352) to its Known Exploited Vulnerabilities catalog on 2026-07-13, the same day AA26-194A was published, with a federal remediation deadline of 2026-07-16 under BOD 22-01.
Weaknesses (CWE)
CWE-120, CWE-787, CWE-352, CWE-284, CWE-306
Target sectors: telecoms, higher education, manufacturing, energy, defense, financial services, government administration, health, critical infrastructure
Target regions: North America, Europe, Asia, Africa, ukraine, poland, united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2018-0171, CVE-2008-4128, T1595, T1595, T1590, T1583, T1190, T1133, T1203, T1059, T1136, T1601