Skip to content
← All Threat Actors
Nation-State high Russia

FSB Center 16

Russian state-sponsored (FSB — Federal Security Service, Centre 16 / FAPSI successor) · Signals intelligence / network infrastructure collection / critical infrastructure pre-positioning

Reports 3
Active Since 2014
Last Reported 19 Jul 2026
Sectors Targeted communications, energy, finance, critical-infrastructure, healthcare

Tactics, Techniques & Procedures (TTPs)

  • Default SNMP community string exploitation: harvesting router configurations via SNMP read access using unchanged default "public"/"private" community strings
  • Cisco Smart Install protocol exploitation: unauthenticated retrieval of running configurations via TCP 4786, using cisco_smart_install modules and known CVEs against unpatched IOS
  • Router configuration exfiltration via TFTP (UDP 69) to FSB-controlled collection infrastructure
  • Collection of routing tables, OSPF/BGP peer relationships, ACL configurations, VPN pre-shared keys, and hashed credentials from exfiltrated configs
  • Long-duration passive collection — harvesting network intelligence without triggering intrusion detection on target endpoints
  • Infrastructure reconnaissance to support subsequent network-level intrusion operations by other Russian state actors
  • Targeting of critical infrastructure and government network perimeters globally through internet-facing management plane exposure

Known Targets

Critical infrastructure operators globally (energy, water, communications, finance, healthcare)Government network infrastructure (US federal agencies, European government networks)Polish energy grid infrastructure (coordinated with broader GRU campaign, 2024–2026)UK telecommunications and government network edge devicesNATO member state network infrastructure

Analyst Notes

FSB Center 16 is the FSB's signals intelligence and network exploitation directorate — the successor to elements of the Soviet FAPSI technical intelligence service. A 19-agency joint advisory (CISA AA26-194A, July 2026, 13 countries) explicitly attributed the SNMP/Smart Install router configuration harvesting campaign to Center 16. The advisory is unusually specific: it names the unit, describes the technique in detail, and was coordinated across Five Eyes, EU, and partner nations. The technique is old and well-understood — its continued effectiveness across critical infrastructure reflects persistently poor router hygiene, not novel capability. A separate FSB Center 16 campaign targeting Polish energy infrastructure (2024–2026) escalated to UK and EU cyber sanctions against named FSB officers in 2026. Exfiltrated router configurations are intelligence assets: they reveal network topology, VPN credentials, and routing architecture that enables future targeted intrusions by other actors.

Also Known As

Center 16FAPSI Centre 16 (historical)Berserk Bear (partial overlap — Dragonfly/Energetic Bear cluster)