An illustration of a hacker sitting in front of computer monitors showing the flags of the United States and Russia. The United States and its allies warn that Russian state-sponsored cyber actors are targeting vulnerable network infrastructure. (Shutterstock/Alexander Geiger)
US and Allies Warn Russian Hackers Are Targeting Critical Infrastructure Routers
The hackers are targeting communications, the defense industrial base, energy, financial services, government services and facilities, and healthcare.
Cybersecurity agencies from the United States and allied countries warned that hackers linked to Moscow could be exploiting vulnerable and poorly configured routers to access critical infrastructure networks. The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Defense Cyber Crime Center (DC3), and international partners, released a joint cybersecurity advisory, “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting.”
It highlighted that Russia’s Federal Security Service and other cyber threat actors are actively targeting vulnerable networking devices, which could threaten critical infrastructure sectors globally.
“CISA continues to work with domestic and global partners to highlight the ongoing threat of nation-state actors targeting vulnerable network devices,” explained Acting Executive Assistant Director for Cybersecurity Chris Butera. “The advisory provides a timely and urgent reminder of actions for critical infrastructure owners and operators to counter Russian state-sponsored activity. CISA urges network defenders to implement mitigation and remediation measures to reduce your attack surface and risk of exploitation.”
The warning was also issued by the cybersecurity agencies of Australia, Canada, the United Kingdom, the Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland, and Sweden.
It wasn’t that critical infrastructure remains most at risk, with Russian hackers—working at the behest of the Kremlin—targeting communications, the defense industrial base, energy, financial services, government services and facilities, and healthcare. Poorly configured routers are used to exploit “common vulnerabilities and exposures” (CVEs), which could allow the threat actors to gain authorized access, to “exfiltrate sensitive configurations, and facilitate malicious activity.”
The US and allied cybersecurity agencies are calling for greater efforts to restrict access, the adoption of stronger authentication and data encryption, to secure weak and vulnerable Internet-facing systems, and to increase the monitoring of suspicious activity.
“Russian state-sponsored cyber actors have spent years quietly extracting configuration data from poorly configured routers across critical infrastructure,” added Assistant Director Brett Leatherman of the FBI’s Cyber Division. “This advisory gives network defenders the visibility to spot this activity and the mitigations to counter it. The FBI will work with our partners to continue to expose this tradecraft and hold these actors accountable.”
The Router Vulnerability Isn’t New
John Strand, owner of Black Hills Information Security, told The National Interest in an email that the story isn’t the vulnerability itself.
“Attacking things like Cisco Smart Install or abusing SNMP isn’t new. Security teams have known about these techniques for more than a decade. The real story is that nation-state attackers continue to succeed by exploiting problems organizations should have fixed years ago,” warned Strand.
He added that much of the problem is that cybersecurity continues to be reactive rather than proactive in addressing these threats. Much of the time is also spent talking to security professionals who are already engaged, and the most vulnerable targets still aren’t part of the conversation.
“Every time we see a large nation-state campaign, there’s a temptation to focus on the newest exploit or the most sophisticated technique,” Strand continued. “In reality, these campaigns are often built around vulnerabilities and insecure configurations that have been public knowledge for years. Attackers aren’t succeeding because defenders lack intelligence. They’re succeeding because too many organizations still struggle with the fundamentals of computer security.”
Router Infrastructure Remains Overlooked
Even as there have been warnings about the dangers from cyber threat actors, much of the network security has overlooked the routers, which remain heavily overlooked, even as these devices serve as the primary gateway for nearly all network traffic. Adversaries, including FSB-linked actors, know this all too well.
“This warning demonstrates that nation-state attackers do not always need a sophisticated zero-day to penetrate critical infrastructure,” explained Ensar Seker, chief information security officer (CISO) at cybersecurity provider SOCRadar.
Seker wrote in an email to The National Interest that in many cases, weak router configurations, default SNMP community strings, outdated firmware, and unnecessary exposure of legacy management protocols provide everything an adversary needs.
Router configuration files have become extremely valuable intelligence.
“They may reveal network topology, administrative credentials, access-control rules, VPN settings, internal IP ranges, and trusted connections,” Seker continued. “Once attackers obtain this information, they can identify pathways into more sensitive systems, prepare targeted follow-on attacks, or establish persistent access while remaining below the visibility of conventional endpoint security tools.”
A Good Cybersecurity Defense Remains Crucial
An ongoing concern is that nation-state hackers, including those from Russia but also from Iran, China, and other countries, target the routers. Unlike desktop or laptop computers, servers, and even mobile smartphones, routers require firmware updates, but these are rarely done.
That creates vulnerabilities in a network, even if the rest of it seems secure.
“Over and over again, we see the same story playing out: infrastructure essential to public health and economic stability being successfully compromised by nation-state adversaries,” said Doc McConnell, head of policy and compliance at cybersecurity researcher Finite State.
“Telecommunications, hospitals, state governments, energy infrastructure, and even the defense industrial base—all under attack for over a decade,” McConnell told The National Interest.
“The broader lesson is that critical infrastructure security can be undermined by a single forgotten or poorly managed edge device,” added Seker. “Network appliances often sit outside normal endpoint detection coverage, making configuration monitoring, external attack-surface visibility, and continuous validation essential.”
To address the issues, infrastructure operators need to disable insecure protocols, implement strong and unique passwords on all their devices, and restrict and monitor access to their management protocols.
Unfortunately, even when the warnings are issued, such as in the new international joint cybersecurity advisory, little action is actually taken.
“We have to do better,” emphasized McConnell. “Our national security is at stake.”
About the Author: Peter Suciu
Peter Suciu has contributed to dozens of newspapers, magazines and websites over a 30-year career in journalism. He regularly writes about military hardware, firearms history, cybersecurity, politics, and international affairs. Peter is also a contributing writer for Forbes and Clearance Jobs. He is based in Michigan. You can follow him on Twitter: @PeterSuciu. You can email the author: Editor@nationalinterest.org.
The post US and Allies Warn Russian Hackers Are Targeting Critical Infrastructure Routers appeared first on The National Interest.