FSB Center 16
Russian state-sponsored (FSB — Federal Security Service, Centre 16 / FAPSI successor) · Signals intelligence / network infrastructure collection / critical infrastructure pre-positioning
Tactics, Techniques & Procedures (TTPs)
- Default SNMP community string exploitation: harvesting router configurations via SNMP read access using unchanged default "public"/"private" community strings
- Cisco Smart Install protocol exploitation: unauthenticated retrieval of running configurations via TCP 4786, using cisco_smart_install modules and known CVEs against unpatched IOS
- Router configuration exfiltration via TFTP (UDP 69) to FSB-controlled collection infrastructure
- Collection of routing tables, OSPF/BGP peer relationships, ACL configurations, VPN pre-shared keys, and hashed credentials from exfiltrated configs
- Long-duration passive collection — harvesting network intelligence without triggering intrusion detection on target endpoints
- Infrastructure reconnaissance to support subsequent network-level intrusion operations by other Russian state actors
- Targeting of critical infrastructure and government network perimeters globally through internet-facing management plane exposure
Known Targets
Analyst Notes
FSB Center 16 is the FSB's signals intelligence and network exploitation directorate — the successor to elements of the Soviet FAPSI technical intelligence service. A 19-agency joint advisory (CISA AA26-194A, July 2026, 13 countries) explicitly attributed the SNMP/Smart Install router configuration harvesting campaign to Center 16. The advisory is unusually specific: it names the unit, describes the technique in detail, and was coordinated across Five Eyes, EU, and partner nations. The technique is old and well-understood — its continued effectiveness across critical infrastructure reflects persistently poor router hygiene, not novel capability. A separate FSB Center 16 campaign targeting Polish energy infrastructure (2024–2026) escalated to UK and EU cyber sanctions against named FSB officers in 2026. Exfiltrated router configurations are intelligence assets: they reveal network topology, VPN credentials, and routing architecture that enables future targeted intrusions by other actors.
Also Known As
MITRE ATT&CK Techniques
Intelligence Reports
CISA AA26-194A: FSB Center 16 Exploiting Default SNMP Credentials to Exfiltrate Router Configs from Critical Infrastructure
A 19-agency joint advisory from 13 countries details how FSB Center 16 has been harvesting router configurations and credentials from critical infrastructure networks globally by exploiting default SNMP community strings and unpatched Cisco Smart Install deployments.
Five Eyes Alert: Russian FSB Router Campaign Targets Critical Sectors Globally
CISA, NSA, FBI, and 15 international partners have issued a joint advisory warning that Russian FSB Center 16 actors are systematically exploiting poorly configured networking devices across energy, communications, healthcare, and financial services.
FSB Center 16 Named in Poland Grid Attack as UK and EU Issue First Joint Cyber Sanctions
The UK and EU have formally attributed a December 2025 cyberattack on Poland's energy grid — which came close to causing a blackout for half a million people — to Russia's FSB Center 16, imposing a landmark coordinated sanctions package targeting Moscow's broader cyber ecosystem.