The US government warns that Russia state hackers are coming after your router

by | Aug 5, 2026 | Technology

The US government warns that Russia state hackers are coming after your router

The Cybersecurity and Infrastructure Security Agency issued a warning Monday regarding ongoing efforts by Russian Federal Security Service operatives to compromise residential routers globally. The advisory was jointly released by CISA alongside cybersecurity authorities from Australia, Denmark, New Zealand, and the United Kingdom. The hacking groups, known by multiple designations including Berserk Bear, Energetic Bear, and Dragonfly, have maintained sustained campaigns targeting poorly configured networking devices across various critical sectors.

The primary attack vector identified involves the exploitation of Simple Network Management Protocol agents on routers that retain default or weak authentication credentials. Attackers employ botnets to scan IP address ranges systematically, identifying vulnerable devices that accept common passwords. Once compromised, these devices can be instructed to execute malicious commands through spoofed network traffic, leveraging the SNMP management protocol to install malware and establish control.

Once operational control is established, the compromised routers serve as exit points for traffic directed at organizations in communications, defense, energy, financial services, and government sectors. By routing malicious activity through apparently legitimate residential devices on trusted IP addresses, attackers substantially reduce the likelihood of detection by firewall systems and other defensive security measures. This technique follows a broader pattern observed in previous years involving both state-sponsored and financially motivated threat actors utilizing residential proxies to obscure attack origins.

CISA recommendations for defending against such compromise include disabling older SNMP versions that lack password encryption in favor of version 3, or disabling SNMP entirely if operationally unnecessary. Additional protective measures encompass disabling Cisco Smart Install functionality, implementing strong authentication credentials, maintaining current firmware versions, and avoiding deprecated networking protocols. The persistent nature of such campaigns represents an ongoing challenge, as previous disruption efforts by government agencies and technology companies have demonstrated limited long-term effectiveness against operators who continually repurpose their infrastructure.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI