The Federal Bureau of Investigation (FBI) is warning of a threat from Russian government cyber actors that is impacting computer networks and critical infrastructure.
The FBI has detected cyber actors Russian Federal Security Service’s (FSB) Center 16 exploiting Simple Network Management Protocol and end-of-life networking devices running an unpatched vulnerability in Cisco Smart Install. Cybersecurity professionals refer to FSB Center 16’s activity by several names including “Berserk Bear” and “Dragonfly” to refer to separate but related cyber activity clusters.
FBI agents detected the group collecting configuration files for thousands of networking devices associated with U.S. entities. In some cases, the group modified configuration files to enable unauthorized access. The group used the unauthorized access to conduct reconnaissance of protocols and applications commonly associated with industrial control systems.
Law enforcement has been aware of FSB Center 16 compromising networking devices for more than 10 years. In 2015, the group deployed custom tools to certain Cisco devices including malware publicly identified as SYNful Knock.
The FBI urges anyone who suspects he or she has been targeted or compromised by a Russian FSB cyber intrusion to report the activity to the local FBI field office or file a report on the FBI’s Internet Crime Complaint Center. The report must include detailed information on configuration changes or malware.