The US government warns that Russia state hackers are coming after your router

by | Aug 11, 2026 | Technology

The US government warns that Russia state hackers are coming after your router

The Cybersecurity and Infrastructure Security Agency issued a warning Monday about ongoing efforts by Russian Federal Security Service operatives to compromise residential and small business routers globally. The effort is coordinated among multiple countries, including Australia, Denmark, New Zealand, and the UK.

The threat actors, tracked under various names including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra, use compromised routers as exit nodes to mask their true locations when targeting organizations in communications, defense, energy, financial services, and government sectors. By routing malicious traffic through seemingly legitimate devices on trusted IP addresses, the attackers reduce the likelihood of being blocked by security defenses and firewalls.

The primary exploitation method involves scanning for routers with active Simple Network Management Protocol agents configured with default or commonly used credentials. Hackers leverage existing botnets of compromised routers to send malicious traffic and install malware on targeted devices. Once controlled, these routers become part of networks of residential proxies used to obscure the origin of attacks and unauthorized activity.

Authorities have faced ongoing challenges in disrupting these operations, with the situation resembling a perpetual cycle where government agencies and technology companies work to remove malware only to have operators quickly establish new botnets. Both Russian and Chinese entities have pursued these activities for years, sometimes competing to maintain control of the same devices.

CISA recommended several protective measures for router owners, including disabling SNMP versions 1 and 2 in favor of version 3, or disabling SNMP entirely when not required. Additional recommendations include disabling Cisco Smart Install, implementing strong passwords, maintaining current firmware, and avoiding other insecure networking protocols.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI