news.mlab.sh
Back to the feed
threat-intel

US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

High
Summary

Russian state-sponsored APT actors are actively targeting routers worldwide to compromise critical infrastructure. These attacks involve exploiting vulnerabilities and leveraging SNMP to steal device configurations and transfer them to servers, with a focus on sectors like communication, defense, and energy. Agencies across the US and its allies are urging immediate action to mitigate the risk.

The US and its allies are issuing a joint warning about a sustained campaign of Russian state-sponsored cyberattacks targeting networking devices, specifically routers, across a wide range of critical infrastructure organizations. The activity is being attributed to the FSB Center 16 threat actors, including groups like Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. These actors are scanning for vulnerable devices and then exploiting known weaknesses to gain unauthorized access and steal configuration data.

The attacks involve sending SNMP set-requests to IP ranges, instructing the SNMP agents on the target devices to copy configurations to a file and transfer it, usually over Trivial File Transfer Protocol (TFTP), to a virtual private server (VPS) or a compromised FTP server. The threat actors have been observed exploiting known vulnerabilities in Cisco devices, including CVE-2008-4128 and CVE-2018-0171, which lead to arbitrary code and command execution. The activity targets critical infrastructure organizations across the communication, defense industrial base, energy, financial, government, and healthcare and public health sectors.

Related activity has been linked to other malicious cyber actors, such as Salt Typhoon. Agencies are advising network defenders to disable Cisco Smart Install on all devices, disable SNMPv1 and SNMPv2, use SNMPv3 with modern encryption standards, use unique passwords for accounts on network devices, configure credentials to be stored securely, and monitor for and alert on logins using local accounts. Additionally, defenders should restrict access to SNMP Object Identifiers (OIDs), restrict management protocols, deny external communications on specific ports on edge firewalls and devices, and keep network device software and firmware updated to patch known vulnerabilities. The NSA recently published an advisory on reducing the risk of SNMP abuse.

Read the full article at SecurityWeek