The US government warns that Russia state hackers are coming after your router

by | Aug 8, 2026 | Technology

The US government warns that Russia state hackers are coming after your router

The Cybersecurity and Infrastructure Security Agency issued a warning Monday regarding ongoing efforts by Russian Federal Security Service cyber actors to compromise residential and small business routers. The hacking groups, tracked under multiple names including Berserk Bear, Energetic Bear, and Dragonfly, have been systematically exploiting vulnerable networking devices to gain unauthorized access for use in attacks against critical infrastructure and sensitive organizations across both public and private sectors. The advisory was released jointly with cybersecurity authorities from Australia, Denmark, New Zealand, and the United Kingdom.

The primary attack vector identified involves hackers scanning IP address ranges for routers with active Simple Network Management Protocol agents that rely on default or weak authentication credentials. Once identified, threat actors send malicious traffic using spoofed addresses to execute malware through the SNMP agent on poorly secured routers. This technique allows attackers to enroll compromised devices into botnets that can be controlled remotely and centrally directed.

Once a router is compromised, attackers utilize it as an exit point for probing and attacking organizations in critical sectors including communications, defense, energy, financial services, and government. By routing malicious traffic through legitimate-appearing devices with trusted IP addresses, the attackers significantly reduce the likelihood of detection and blocking by firewalls and other defensive security measures. This use of residential proxies to obscure the true origin of attacks has become a standard tactic among state-sponsored operators.

CISA recommended several defensive measures for router users, including disabling Simple Network Management Protocol versions 1 and 2, which lack password encryption and basic security practices. The agency advocated for exclusive use of SNMP version 3 when the protocol is necessary, or preferably disabling it entirely. Additional protective steps include deactivating Cisco Smart Install functionality, implementing strong authentication credentials, maintaining current firmware versions, and avoiding other insecure networking protocols.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI