FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable routers — joint UK & allied advisory

FSB Centre 16 (Berserk Bear/Energetic Bear) targets global (TL-2026-2375), also tracked as Operation Poland Energy Grid, is a high-severity tracked intrusion set scored CVSS 9.8, first published 2026-07-13. It is attributed to FSB Centre 16 (Russia) with high confidence, affects Cisco IOS and IOS XE Software (Smart Install), references 2 CVEs (CVE-2018-0171, CVE-2008-4128), maps to 21 MITRE ATT&CK techniques (T0802, T1003, T1018), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2375

Threat ID
TL-2026-2375
Also known as
Operation Poland Energy Grid, FSB Information Security Center Campaign, Static Tundra Router Campaign
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
FSB Centre 16
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
communications, defense, defense-industrial-base, energy, electric-utilities, financial-services, government administration, government-facilities, health, renewable-energy
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

Malware and tooling: Backdoor.Oldrea - S0093, DynoWiper - S9038, LazyWiper, rsocx2

The UK NCSC and 18 agencies from 12 countries warn that Russian FSB Centre 16 actors (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra) are actively exploiting vulnerable routers globally — scanning for devices with default or weak SNMP community strings, exploiting Cisco Smart Install (CVE-2018-0171, CVSS 9.8), and exfiltrating device configurations via TFTP to actor-controlled VPS infrastructure. The UK and EU member states formally attributed the December 2025 destructive attack on Poland's energy grid (DynoWiper/LazyWiper wipers, 30+ wind/PV farms, CHP plant serving 500,000 customers) to Centre 16, and the UK sanctioned 24 individuals and entities in the first joint UK-EU cyber sanctions package.

How FSB Centre 16 (Berserk Bear/Energetic Bear) targets global works

FSB Centre 16 (Russia's Federal Security Service Information Security Center) is conducting a persistent global campaign targeting inadequately configured networking devices, primarily routers, to gain initial access to critical national infrastructure (CNI) networks. The actors scan internet IP ranges for SNMP agents accepting default or common community strings, sending SNMP Set-Requests from spoofed IP addresses via proxies. These requests use OID 1.3.6.1.4.1.9.9.96.1.1 (Cisco Config Copy) to instruct vulnerable devices to copy their configuration — often saving it as 'config.bkp' or 'output.txt' — and exfiltrate it via TFTP to actor-controlled leased VPS servers or compromised FTP servers. The configuration files contain device credentials including weakly-hashed Cisco Type 7 and plaintext Type 0 passwords, enabling further compromise.

In addition to SNMP abuse, the actors exploit known vulnerabilities including CVE-2018-0171 (Cisco Smart Install remote code execution, CVSS 9.8, on CISA KEV) and CVE-2008-4128 (Cisco IOS CSRF targeting EOL devices) to compromise Cisco devices, and exploit web management portal flaws on various network equipment. The campaign targets CNI sectors including communications, defence, energy, financial services, government, and healthcare.

On 29 December 2025, this actor cluster conducted its first publicly documented destructive attack — a coordinated assault on Poland's energy sector targeting 30+ wind and photovoltaic farms, a large combined heat and power (CHP) plant supplying heat to approximately 500,000 customers, and a manufacturing company. The attackers gained initial access via FortiGate VPN concentrators using compromised credentials without MFA, exploited shared VPN credentials across multiple facilities, and leveraged privileged AD accounts to deploy DynoWiper (native Windows binary using Mersenne Twister PRNG for pseudorandom file overwriting) and LazyWiper (PowerShell-based script with C# WriteRandomBytes function) via GPO-based scheduled tasks. OT devices including Hitachi Energy RTU560 controllers, Moxa NPort 6xxx serial servers, and Mikronika RTU/HMI panels were also directly targeted by uploading corrupted firmware (RTU560) or factory-resetting devices (NPort 6xxx), permanently damaging controllers. The CHP plant attack was blocked by ESET PROTECT EDR before wiper malware could detonate. Approximately 1.2 GW of generation capacity was attacked — roughly 5% of Poland's total capacity.

On 13 July 2026, the UK government jointly with EU member states formally attributed the Poland energy grid attack to FSB Centre 16, and the UK Foreign Office sanctioned 24 individuals and entities including FSB Centre 16-linked actors, GRU Unit 29155 leadership, Lumma Stealer operators, and Rybar LLC propagandists. The same day, a joint cybersecurity advisory co-signed by 19 agencies from 12 countries (led by NSA, CISA, FBI, NCSC-UK, and partners from Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, New Zealand, Poland, and Sweden) was published detailing FSB Centre 16's router exploitation TTPs and recommending mitigations including SNMPv3 migration, Smart Install disablement, and multi-factor authentication.

Attribution of the Poland energy attack to Centre 16 is contested by ESET, which assesses with medium confidence that the DynoWiper malware's TTPs align with GRU Unit 74455 (Sandworm/Seashell Blizzard), citing links to the ZOV wiper previously used in Ukraine. CERT Polska's technical attribution is based on overlaps in compromised VPS infrastructure, routers, traffic patterns, and anonymizing infrastructure consistent with the Centre 16-linked cluster. The broader consensus across the UK government, EU member states, CERT Polska, and CISA/NATO partners attributes the router scanning campaign unequivocally to FSB Centre 16, while the Poland attack is more complex due to apparent inter-service tool-sharing or coordinated operations between Russian intelligence agencies.

MITRE ATT&CK techniques used in TL-2026-2375

Collection

T0802 Automated Collection; T1602.001 SNMP (MIB Dump); T1602.002 Data from Configuration Repository: Network Device Configuration Dump

Credential Access

T1003 OS Credential Dumping

Discovery

T1018 Remote System Discovery

Defense Evasion

T1027 Obfuscated Files or Information

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Execution

T1053 Scheduled Task/Job; T1569 System Services

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

command-and-control

T1090 Proxy

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery; T1561 Disk Wipe

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1584.008 Network Devices; T1588.005 Obtain Capabilities: Exploits

Reconnaissance

T1595.001 Active Scanning: Scanning IP Blocks; T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

  • Cisco — IOS and IOS XE Software (Smart Install)
    Vulnerable versions: Multiple versions via Smart Install feature
    Fixed in: See cisco-sa-20180328-smi2 for fixed releases
  • Cisco — 871 Integrated Services Router (IOS 12.4)
    Vulnerable versions: 12.4
    Fixed in: Upgrade to supported hardware — EOL device
  • Fortinet — FortiGate VPN Concentrators
    Vulnerable versions: Multiple versions without MFA enforcement
    Fixed in: Enforce MFA on all VPN users; upgrade to latest firmware
  • Hitachi Energy — RTU560 Remote Terminal Units
    Vulnerable versions: 12.6.6.0; 12.7.3.0; 13.1.1.0; 13.5.2.0
    Fixed in: Change default credentials; upgrade firmware
  • Moxa — NPort 6xxx Serial Device Servers
    Vulnerable versions: All versions with default credentials and enabled web interface
    Fixed in: Change default credentials; disable web interface if not required

Remediation for FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

Patches

  • Apply Cisco fixed software releases for CVE-2018-0171 (Cisco Smart Install RCE) per cisco-sa-20180328-smi2
  • Upgrade all FortiGate VPN firmware to latest recommended version
  • Apply manufacturer firmware updates for Hitachi Energy RTU560, Moxa NPort 6xxx, and Mikronika devices
  • Use Cisco hashing type 8 for device credentials; eliminate types 0, 4, and 7

Immediate actions

  • Disable SNMPv1 and SNMPv2 on all network devices; migrate to SNMPv3 with authPriv
  • Disable Cisco Smart Install on all devices (TCP 4786) if not in use
  • Block at edge firewalls: UDP 69 (TFTP), TCP 4786 (SMI), UDP 161/162 (SNMP), TCP/UDP 10161/10162 (SNMPv3)
  • Change all default SNMP community strings across all network devices
  • Change default credentials on all OT/ICS controllers (RTUs, HMIs, protection relays, serial servers)
  • Enforce multi-factor authentication on all VPN and remote access gateways

Workarounds

  • If SNMPv1/v2 cannot be disabled immediately, restrict SNMP access to management IP ranges via ACLs and use read-only community strings only
  • If TFTP blocking is operationally infeasible, implement strict monitoring and allow-listing of TFTP destinations
  • Use MIB allow-listing to restrict SNMP OID access; monitor for inbound SNMP Set-Requests containing OID 1.3.6.1.4.1.9.9.96.1.1
  • Implement network-level monitoring for unexpected config.bkp or output.txt file creation on network devices

Longer-term hardening

  • Implement network segmentation between IT and OT environments at every facility
  • Deploy EDR/XDR with auto-isolation on all OT-adjacent IT systems
  • Restrict management protocols via ACLs to out-of-band management networks only
  • Replace end-of-life network devices (EOL Cisco hardware with CVE-2008-4128 exposure)
  • Implement centralized authentication (RADIUS/TACACS+) with MFA for all network device administration
  • Adopt attack surface management and continuous SNMP monitoring via IDS/IPS
  • Implement immutable/air-gapped backups with 90+ day retention for OT environments

CVEs associated with FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

CVE-2018-0171, CVE-2008-4128

Weaknesses (CWE) in FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

CWE-787, CWE-352

Timeline of FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

  • Energetic Bear/Dragonfly activity first observed targeting global energy sector organizations; early reconnaissance and espionage operations
  • Havex RAT identified; supply chain compromise of ICS vendor software replaced legitimate installers with trojanized versions containing the Havex backdoor
  • Kaspersky publishes 'Energetic Bear — more like a Crouching Yeti' detailing the actor's OPC scanning capabilities and global energy sector espionage campaign
  • CVE-2018-0171 (Cisco Smart Install RCE, CVSS 9.8) disclosed; Cisco Smart Install feature allows unauthenticated remote attackers to trigger device reload or execute arbitrary code via crafted TCP 4786 messages
  • US DOJ indicts three FSB officers and a Russian Federation Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM) employee for energy sector cyber targeting campaigns
  • March-July 2025: Extensive reconnaissance including collection of OT modernization documentation, SCADA network diagrams, control device configurations; Active Directory privilege escalation to full domain administrative accounts
  • FSB Centre 16 gains initial access to Polish CHP plant IT infrastructure via FortiGate VPN concentrator using compromised credentials; no MFA enforced; shared VPN credentials across multiple energy facilities
  • FBI PSA I-082025-PSA warns of FSB Centre 16 actors targeting networking devices globally via SNMP scanning, Cisco Smart Install exploitation, and configuration exfiltration via TFTP
  • Autumn 2025: Propagation to Polish wind and photovoltaic farms via shared VPN credentials; automated IP scanning; standardized FortiGate configurations across facilities enabled lateral movement
  • Coordinated destructive attack on Poland's energy sector: 30+ wind/PV farms, a CHP plant supplying ~500,000 heat recipients, and a manufacturing facility hit. DynoWiper (Mersenne Twister PRNG file overwriting) and LazyWiper (PowerShell-based) deployed via GPO scheduled tasks. Hitachi RTU560 firmware corrupted, Moxa NPort 6xxx and Mikronika devices bricked. CHP plant attack blocked by ESET PROTECT EDR
  • CERT Polska publishes Energy Sector Incident Report detailing the December 2025 attack, including DynoWiper and LazyWiper analysis, infrastructure IOCs, and attribution to the Static Tundra/Berserk Bear cluster
  • NSA, CISA, FBI, NCSC, DC3, and 14 partner agencies from 12 countries publish joint advisory 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting' (AA26-194A) detailing FSB Centre 16 TTPs and mitigations; CVE-2008-4128 added to CISA KEV
  • UK government sanctions 24 individuals and entities: FSB Centre 16 actors, GRU Unit 29155 leadership (Vyacheslav Stafeyev, Ivan Senin, Ivan Kasyanenko), Lumma Stealer operators, and 10 individuals behind Rybar LLC propagandists
  • UK and EU member states formally attribute December 2025 Poland energy grid attack to Russia's FSB Centre 16; first coordinated UK-EU cyber sanctions package

Sources cited for FSB Centre 16 (Berserk Bear/Energetic Bear) targets global

More in threat intel

Detection coverage for TL-2026-2375

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2375 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats