
The Cybersecurity and Infrastructure Security Agency issued an advisory Monday alerting residential and small business router owners about ongoing compromise campaigns by Russian government-affiliated hackers. The warning came with coordination from international partners including Australia, Denmark, New Zealand, and the United Kingdom.
The hacking groups, tracked under multiple designations such as Berserk Bear, Energetic Bear, and Ghost Blizzard, are part of Russia’s Federal Security Service Center 16. These actors exploit poorly configured networking equipment to gain access to critical infrastructure networks across communications, defense, energy, financial services, and government sectors. Once compromised, routers serve as exit nodes through which attackers funnel malicious traffic, allowing them to evade detection by firewalls and other security defenses.
The primary exploitation method involves scanning internet protocol ranges for devices running Simple Network Management Protocol with default or weak authentication credentials. SNMP agents allow administrators to monitor and control network devices, but when improperly secured, they become entry points for attackers to deploy malware and enroll routers into botnets. The attackers leverage these compromised devices as residential proxies to obscure the origin of their operations against high-value targets.
CISA provided multiple mitigation recommendations for device owners. The agency stressed disabling SNMP versions 1 and 2, which lack password encryption and proper security protocols, in favor of version 3 or complete disablement if the protocol is unnecessary. Additional protective measures include disabling Cisco Smart Install features, implementing strong authentication credentials, maintaining current firmware versions, and avoiding other insecure networking protocols. Officials noted that ongoing efforts by Google and government agencies to disrupt router botnets continue to operate on a reactive basis as threat actors repeatedly rebuild their infrastructure.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI