US Government Warns: Russia State Hackers Are Coming After Your Router
CISA warns that Russian FSB cyber actors are mass-compromising home and small office routers to use as proxies for attacks against critical infrastructure.
CISA Warning
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about Russian state hackers mass-compromising routers worldwide. Russian FSB Center 16 cyber actors are exploiting poorly configured networking devices to attack critical infrastructure.
Known Groups
The hacking groups are tracked under various names: Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. They have been conducting cyber attacks against critical infrastructure for years.
Attack Method
Attackers scan IP ranges for active SNMP agents that accept common or default community strings. Compromised routers are used as residential proxies to obscure attacks against sensitive organizations in public and private sectors.
Global Scope
The advisory was co-issued by governments from Australia, Denmark, New Zealand, and the UK, highlighting the global scale of the problem.
Special Threat to Georgia
This warning is especially relevant for Georgia. Russia occupies 20% of Georgian territory, and cyber attacks against Georgia are frequent. In 2019, Georgia experienced a massive cyber attack that disabled thousands of websites. Georgian businesses and citizens should take immediate steps to secure their routers: change default passwords, update firmware, and disable SNMP if not needed.