Russian hackers are targeting routers to infiltrate critical infrastructure, CISA warns
A forgotten router could give hackers a foothold inside critical telecom networks.

Image by Cybernews.
- Russian hackers are exploiting forgotten routers to quietly map and infiltrate critical infrastructure networks.
- Stolen router configurations can expose credentials, VPN settings, internal IP ranges, and trusted connections.
- US and international allies warn that one vulnerable edge device can create long-term access for espionage or disruption.
- EU sanctions also targeted bulletproof hosting providers accused of supporting Russia-linked cyberattacks worldwide.
Russian state hackers are quietly exploiting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, according to a new security warning issued Monday from the US cybersecurity watchdog and allied nations.
The joint cybersecurity advisory – issued by the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA, DC3, and eight allied nations – is warning defenders that Russian state-sponsored actors continue to target internet-facing routers – all to steal sensitive network information and establish long-term access within victim networks.
“Russian state-backed actors are getting quieter, more patient and more deliberate,”said Nick Tausek, Lead Security Automation Architect at Swimlane.
Tausek also says the goal of these infrastructure attacks is "not always immediate disruption, but often about creating options when geopolitical pressure rises.”
“Exposed routers and weak SNMP settings give them a low-profile way to learn how a network is built while maintaining access they can use at a more strategic moment," he says.
Russian hackers target overlooked routers
In the past year, threat actors “attributed to the Russian Federal Security Service's (FSB) Center 16” were detected collecting configuration files from thousands of networking devices associated with US critical infrastructure organizations, the FBI said.
Providing a detailed list of tactics, techniques, and procedures to help counter the active threat, the agency names half a dozen Russian-linked threat groups known among the security community and actively carrying out these types of opportunistic attacks:
- Berserk Bear
- Energetic Bear
- Crouching Yeti
- Dragonfly
- Ghost Blizzard
- Static Tundra
The most targeted critical sectors are said to include communications, defense, energy, financial services, healthcare, public health, and government services and facilities, with state and local governments a favored target of Moscow.
Ensar Seker, President of Research and CISO at SOCRadar, says the latest warning proves that “nation-state attackers don’t always need a sophisticated zero-day to penetrate critical infrastructure.”
“In many cases, weak router configurations, default SNMP community strings, outdated firmware, and unnecessary exposure of legacy management protocols provide everything they need,” Seker explains.
"Router configuration files are extremely valuable intelligence,"warns Seker.
He says the files can reveal a plethora of sensitive network information, including “network topology, administrative credentials, access-control rules, VPN settings, internal IP ranges, and trusted connections.”
The threat actors can use those data points to “identify pathways into more sensitive systems, prepare targeted follow-on attacks, or establish persistent access while remaining below the visibility of conventional endpoint security tools,” he points out.
Why router compromises matter
CISA warns that edge devices are often overlooked despite serving as critical gateways into enterprise and critical infrastructure networks, providing attackers with a platform for future espionage, lateral movement, or disruptive cyber operations.
Seker says the "broader lesson is that critical infrastructure security can be undermined by a single forgotten or poorly managed edge device."
The CISO urges defenders to treat routers and other network appliances as "high-value security assets – not passive infrastructure."
“Network appliances often sit outside normal endpoint detection coverage, making configuration monitoring, external attack-surface visibility, and continuous validation essential,” Seker said.
Tausek stresses that
"critical infrastructure operators must not treat router hygiene as routine maintenance."
“One compromised device can open pathways into essential services and put public safety at risk,” he explains, adding that "disabling legacy protocols, patching devices, and restricting management access are the foundation."
From there, Tausek says “teams need a clearer view across their tools and faster ways to investigate suspicious activity.”
The agencies further urged organizations to inventory internet-facing devices, replace older SNMP versions with properly configured SNMPv3, remove default community strings, restrict management access, disable unnecessary services, keep firmware up to date, and monitor for unauthorized configuration changes.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
EU targets Russia’s cyber support network
The warning comes as the Council of the European Union on Monday also imposed new sanctions on nine individuals and four entities accused of “carrying out, enabling and facilitating cyber-attacks” against EU member nations, the US and other international partners on behalf of Russia.
Among those sanctioned were bulletproof hosting provider Media Land LLC, its owner Alexander Volosovik, and its sister company ML.Cloud, the Council’s announcement said.
The sanctions also targeted several threat groups and individuals linked to the GRU and other cyber operations, including those involved in the development and distribution of several known malware strains:
- Z-Pentest (pro-Russia hacktivist group)
- Cyber Army of Russia Reborn (CARR)
- GRU Unit 29155
- LLC “Impuls” (Russian tech company)
- LummaC2 infostealer malware
- TrickBot banking trojan and malware ecosystem
- Conti ransomware
Has your password leaked?