The US government warns that Russia state hackers are coming after your router

by | Jul 25, 2026 | Technology

The US government warns that Russia state hackers are coming after your router

Federal cybersecurity officials issued an alert regarding ongoing compromise campaigns targeting home and small office routers by Russian state-sponsored actors. The Cybersecurity and Infrastructure Security Agency stated that hackers affiliated with the Russian Federal Security Service continue to exploit poorly configured and vulnerable networking devices globally, with the aim of gaining access to critical infrastructure networks across multiple sectors.

The campaign employs a well-established technique in which hackers scan for internet protocol ranges running Simple Network Management Protocol agents that rely on default or weak authentication credentials. Once compromised, routers serve as exit nodes for malicious traffic directed at organizations in communications, defense, energy, financial services, and government sectors. By routing attacks through these residential devices, threat actors obscure their true origin points and reduce the likelihood of detection by security defenses and firewalls.

CISA attributed the operations to groups tracked under multiple designations, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was issued jointly with international partners including Australia, Denmark, New Zealand, and the United Kingdom. Officials noted that similar campaigns have been conducted by Chinese state actors in previous years.

The agency provided recommendations to reduce vulnerability, with primary emphasis on disabling SNMP versions 1 and 2 due to weak encryption standards and password protection mechanisms. Alternative measures include upgrading to SNMP version 3, disabling Cisco Smart Install protocols, implementing strong authentication credentials, maintaining current firmware versions, and removing unnecessary networking protocols. The ongoing compromise campaigns reflect broader patterns in which state actors and criminal groups utilize residential proxies to facilitate operations against sensitive targets.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI