Federal authorities have issued a global warning that state-sponsored hackers affiliated with Russia’s Federal Security Service (FSB) are systematically compromising home and small office routers to build vast proxy networks that obscure cyberattacks against critical infrastructure. The advisory, released Monday by the US Cybersecurity and Infrastructure Security Agency (CISA) and co-signed by cybersecurity agencies in Australia, Denmark, New Zealand, and the United Kingdom, details a persistent campaign targeting poorly configured networking devices worldwide.
Russia’s FSB Targets Consumer Routers for Covert Operations
The hacking groups, tracked under names including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra, are actively exploiting vulnerable routers to anonymize malicious traffic. “Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” CISA stated in the joint advisory. The compromised devices are used to form residential proxy networks, making it difficult for defenders to distinguish malicious traffic from legitimate user activity.
How the Attack Works: SNMP Vulnerability Exploitation
The primary attack vector involves scanning IP ranges for devices with active Simple Network Management Protocol (SNMP) agents that still accept default or weak authentication credentials. SNMP is a standard protocol used to collect and organize information about managed network devices, but it can also be used to modify device behavior. Hackers leverage existing router botnets to send malicious traffic from spoofed addresses, using the SNMP agent on misconfigured routers to deploy malware. This technique effectively enrolls the targeted device into a larger botnet, which is then used for further scanning and attacks.
A Persistent Game of Whack-a-Mole
The compromise of consumer and small office routers is not a new phenomenon. Both Russian and Chinese state-sponsored hacking groups have been engaging in prolonged tugs-of-war for control of these devices for years. While the US government has occasionally issued covert commands to disinfect routers, and major technology companies have worked to disrupt the massive botnets controlling them, these efforts have proven to be largely reactive. “The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones,” the advisory notes, highlighting the persistent and scalable nature of the threat.
Why This Matters for Home and Small Office Users
For users in the US, UK, Australia, and Canada, the warning underscores that consumer-grade networking equipment is now a primary target for state-sponsored intelligence operations. A compromised router can be used to intercept unencrypted web traffic, redirect users to malicious websites, and serve as a launch point for attacks against government agencies, energy grids, and private sector organizations. The risk is not simply that an individual’s internet connection is used without their knowledge; it is that their device becomes an active weapon in a broader geopolitical campaign.
What Affected Users Should Do Now
Securing home and small office routers requires immediate action. Users should disable remote administration features unless absolutely necessary, change default administrator credentials to strong, unique passwords, and disable SNMP if it is not actively required. It is also critical to update router firmware to the latest version and enable automatic updates where available. For anyone who suspects their router may be compromised, a factory reset followed by a manual firmware update is the most decisive step. Additionally, using a reputable no-log VPN service with AES-256 encryption and a kill switch can help protect traffic from interception even if the router is compromised. Implementing multi-layer endpoint protection on all connected devices provides another critical layer of defense against follow-on attacks.