
The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning regarding ongoing efforts by Russian state-sponsored cyber actors to compromise routers used in homes and small office environments. The hacking operations, attributed to the Russian Federal Security Service’s Center 16 division and tracked under various designations including Berserk Bear, Energetic Bear, and other monikers, have been systematically targeting networking devices worldwide to facilitate attacks on critical infrastructure sectors.
The advisory, released on Monday, was jointly issued by CISA along with cybersecurity authorities from multiple countries including Australia, Denmark, New Zealand, and the United Kingdom. The compromised routers serve as tools for obscuring malicious activities directed at organizations in communications, defense, energy, financial services, and government sectors. By gaining control of these residential and small office devices, threat actors can route their attacks through legitimate-appearing network addresses, making it more difficult for security defenses such as firewalls to detect and block the malicious traffic.
The primary attack vector identified involves threat actors scanning networks for routers running Simple Network Management Protocol agents that are configured with default or weak authentication credentials. Once a router is compromised through this method, the actors integrate it into botnets that can be remotely controlled to launch further attacks. The practice of repurposing compromised residential routers for attack infrastructure is not new, with both Russian and Chinese government actors having engaged in similar campaigns for extended periods, with security defenders and technology companies engaged in ongoing efforts to disrupt the associated botnets.
CISA provided recommendations for users to protect their devices, emphasizing the importance of disabling older, unencrypted versions of SNMP protocols, implementing strong authentication credentials, regularly updating device firmware, and disabling unnecessary networking features. The agency noted that completely disabling SNMP is preferable unless the protocol is specifically required for operational purposes.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI