Russian State Actors Targeting Network Infrastructure

Jul 15, 2026

Threat Notice

International cyber security agencies, including New Zealand’s NCSC, have issued a joint advisory warning that Russian state-sponsored cyber actors continue to target vulnerable and poorly configured routers and network devices worldwide. Organisations are encouraged to review their network infrastructure security and implement recommended hardening measures.

What happened?

Russian Federal Security Service (FSB) Centre 16 cyber actors have been observed targeting vulnerable and poorly secured network infrastructure worldwide. Their activity focuses on identifying routers and other internet-facing networking devices that can be exploited to gain unauthorised access to organisational environments. Common access methods include:

  • Weak or default SNMP community strings.
  • Exposed management interfaces.
  • Legacy management protocols.
  • Unpatched networking devices.
  • Known vulnerabilities affecting network infrastructure.

Following compromise, access may be used to collect device configurational information, gain visibility of internal networks, and establish a foothold for further malicious activity.

What are we seeing now?

This activity forms part of long-running cyber operations focused on maintaining access to and collecting information from network infrastructure worldwide. Despite being a well-understood threat, the continued success of these operations demonstrates that insecure or poorly maintained network devices remain a viable target. The activity has been observed across multiple sectors, including:

  • Communications
  • Defence
  • Energy
  • Financial services
  • Government
  • Healthcare

The latest reporting highlights that many of the weaknesses being targeted are not new. Instead, they reflect ongoing challenges associated with maintaining secure configurations, maintaining legacy technologies, and ensuring network infrastructure is regularly reviewed and updated.

Why does this matter to you?

Routers and other network infrastructure devices are often overlooked; however, they play a critical role in how organisations communicate, connect to the internet, and managed access between networks. A compromised device can provide threat actors with opportunities to:

  • Gather information about network architecture and connected systems.
  • Identify additional pathways into the environment.
  • Establish persistent access for future activity.
  • Support broader intrusion, reconnaissance, or collection objectives.

While this activity has been observed against critical infrastructure organisations, the underlying weaknesses are not unique to those environments. Any organisation operating internet-facing network infrastructure should ensure these devices are securely configured, regularly maintained, and included within routine security reviews.

What can you do?

  • Review internet facing routers and network devices for unnecessary exposure and externally accessible management services.
  • Strengthen authentication controls by replacing default or weak credentials and reviewing the use of technologies such as SNMP to ensure secure configurations are in place.
  • Restrict administrative access to trusted users and networks wherever possible.
  • Disable unnecessary or legacy services and protocols, including vendor-specific functionality that is no longer required, such as Cisco Smart Install where present.
  • Apply software and firmware updates to address known vulnerabilities affecting network infrastructure.
  • Review logging and monitoring capabilities to detect unauthorised administrative activity and configuration changes.
  • Confirm routers and network infrastructure are included within vulnerability management and security review activities.

Where can you find out more?

The following sources informed DEFEND’s assessment and provide additional context on the situation:

Download the Insight

Fill out the form below to read the Insight

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
By submitting , I agree to the process of my personal data by DEFEND as described in the Privacy Policy.

Get in touch with us

Contact Us
icon-angle icon-bars icon-times