Skip to content
EternaEdge

National security

A decade inside the routers: the FSB advisory and the defense industrial base

20 July 2026 · 2m read · By EternaEdge

On July 13, CISA, NSA, FBI, and partner agencies from twelve countries published joint advisory AA26-194A, attributing a campaign of more than ten years against poorly configured network devices to Russia's FSB Center 16 — the actor tracked commercially as Berserk Bear, Static Tundra, Dragonfly, and Ghost Blizzard. The tradecraft is unglamorous and effective: scanning for SNMP agents with default or weak community strings, abusing Cisco Smart Install, and exfiltrating full device configurations over TFTP.

The advisory names its most-at-risk sectors plainly: communications, the defense industrial base, energy, financial services, government facilities, and healthcare.

Why a router campaign is an intelligence campaign

A stolen router configuration is a map — credentials, network topology, trust relationships, the location of everything worth taking next. A decade of quiet configuration harvesting is not opportunistic crime; it is patient intelligence preparation, positioning for access that may be exercised years later or never. That is what distinguishes a state service running network reconnaissance from a ransomware crew: the product is the option, not the incident.

For defense suppliers, the exposure is structural

  • The campaign thrives at the network edge of smaller organizations — exactly where thousands of subcontractors in the defense supply chain live, below the security budgets of the primes they support.
  • Legacy protocol hygiene (disabling Smart Install, moving to SNMPv3, blocking the ports the advisory lists) is cheap relative to what a harvested configuration gives away.
  • An intrusion that produces no visible damage still warrants a counterintelligence question: what does this actor's decade of collection say about which programs and suppliers it values?

That question — what the adversary's preparation reveals about their intent — is the one event-based tooling never asks. A configuration pulled from a parts supplier's edge router is a minor cyber event and a significant intelligence signal, and which one it gets treated as depends entirely on whether anyone connects it to the program that supplier feeds. Correlating cyber reconnaissance to the missions and suppliers it actually touches is the core of counterintelligence-aware cyber threat intelligence, and it is the reason we build cyber and counterintelligence into one picture rather than two tools.

Ten years of patient collection deserves an equally patient response: know your edge, close the legacy doors, and treat quiet reconnaissance as the early warning it is.

Next step

See it run on your domains of protection.

A demo walks the full arc — signal to case to defensible record — with the domains you protect in the room.