
The Cybersecurity and Infrastructure Security Agency issued an advisory Monday warning that Russian Federal Security Service actors are actively exploiting poorly configured and vulnerable routers worldwide to compromise critical infrastructure networks across multiple sectors. The hacking groups, tracked under various names including Berserk Bear, Energetic Bear, Crouching Yeti, and others, have been engaged in prolonged campaigns to commandeer residential networking devices. The warning was issued jointly with cybersecurity authorities from Australia, Denmark, New Zealand, and the United Kingdom.
The primary attack vector identified involves hackers scanning IP ranges for Simple Network Management Protocol agents that rely on common or default authentication credentials. Once discovered, these vulnerable configurations allow attackers to deploy malware through spoofed traffic, enabling them to seize control of the targeted devices. After gaining access, the compromised routers are incorporated into botnets and used as exit nodes for attacks against organizations in the communications, defense, energy, financial services, and government sectors.
By routing malicious traffic through compromised residential devices on trustworthy IP addresses, attackers can obscure their true origins and evade detection by firewalls and other security defenses. This technique, often referred to as using residential proxies, has become a standard tool in state-sponsored cyber operations. Similar tactics have been employed by other foreign governments and financially motivated criminal groups in recent years.
The advisory recommended that users take several protective measures, with disabling SNMP versions 1 and 2 being among the most critical steps, as these protocols transmit credentials without encryption. Alternatively, users should disable SNMP entirely unless required for specific operational needs. Additional recommendations include disabling Cisco Smart Install on all devices, implementing strong authentication credentials, maintaining current firmware versions, and avoiding other insecure networking protocols.
U.S. government agencies have previously undertaken covert operations and coordinated with technology companies like Google to disrupt router botnets, but such efforts have proven to be temporary measures as attackers quickly establish replacement infrastructure.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI