ctipilot.ch

Static Tundra

actor · actor:static-tundra single-source-national-cert

Russian FSB Centre 16 network-device cluster (Cisco Talos: Static Tundra; CrowdStrike/FBI: Berserk Bear/Energetic Bear; Symantec: Dragonfly; Microsoft: Ghost Blizzard) that opportunistically compromises internet-facing routers via default/weak SNMP community strings and Cisco Smart Install (CVE-2018-0171), exfiltrating device configurations over TFTP, across communications, defence, energy, financial, government and healthcare sectors. Detailed in a 19-agency (13-country) joint Cybersecurity Advisory (2026-07-13) and formally attributed by CERT Polska/UK/EU to the destructive 29 December 2025 Poland energy-grid attack. FSB Centre 16 is a parent unit spanning multiple tracked clusters (Static Tundra and, separately, Turla/Secret Blizzard), not a single group.

Aliases: Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard

Coverage timeline
4
first 2026-07-13 → last 2026-08-24
Peak priority
high
3 high · 1 notable
Sources cited
15
14 hosts
Sections touched
3
deep-dive, updates, weekly-top-stories
Co-occurring entities
5
see Related entities below
ATT&CK techniques
40
pinned v19.2 · see below
2026-07-134 appearances2026-08-24

ATT&CK techniques

40 techniques observed across 4 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595.001Active Scanning: Scanning IP Blocks×1

Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Resource Development TA0042

T1583.003Acquire Infrastructure: Virtual Private Server×1

Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1584.004Compromise Infrastructure: Server×1

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Evidence: 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1584.008Compromise Infrastructure: Network Devices×1

Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1588.005Obtain Capabilities: Exploits×1

Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1189Drive-by Compromise×2

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1566Phishing×2

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Execution TA0002

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1204.004User Execution: Malicious Copy and Paste×1

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions—such as prompts to fix errors or complete CAPTCHAs—that instead instruct the user to copy and paste malicious code.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1133External Remote Services×2

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Defense Impairment TA0112

T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1601.001Modify System Image: Patch System Image×1

Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Credential Access TA0006

T1003OS Credential Dumping×1

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1003.001OS Credential Dumping: LSASS Memory×1

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1558Steal or Forge Kerberos Tickets×1

Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Lateral Movement TA0008

T1021.002Remote Services: SMB/Windows Admin Shares×1

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Collection TA0009

T1114.002Email Collection: Remote Email Collection×1

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1213.002Data from Information Repositories: Sharepoint×1

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1602.001Data from Configuration Repository: SNMP (MIB Dump)×2

Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1602.002Data from Configuration Repository: Network Device Configuration Dump×1

Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Exfiltration TA0010

T1048Exfiltration Over Alternative Protocol×1

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×2

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1495Firmware Corruption×1

Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

T1561Disk Wipe×1

Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted.

Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗

Story timeline

  1. 2026-08-24Switzerland's federal cyber authority reports the public sector as still the largest share of mandatory critical-infrastructure notifications, and devotes its half-year report to two things a Swiss defender can act on: the anatomy of the Polish energy sabotage, and a crypto-theft playbook that recruits its victims on LinkedIn
    deep-diveBACS report: the public sector remains the largest share of Swiss mandatory CI reports at 19.4%, and basic hygiene would have stopped the Poland sabotage
  2. 2026-07-19Russian state-nexus pre-positioning against European critical infrastructure reached a new attribution-and-consequence threshold this week — router hijacking, the Turla espionage cluster, the Poland grid attack and camera surveillance all named on the same day the EU and UK imposed their first joint cyber-sanctions
    weekly-top-storiesRussian FSB pre-positioning against European CI went public — router hijacking, the Turla and Poland-grid attributions, and the first joint EU/UK sanctions
  3. 2026-07-13FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
    deep-dive19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland's Dec-2025 grid sabotage
  4. 2026-07-13France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions
    updatesANSSI publishes CERTFR-2026-CTI-005 on FSB Centre 16's Turla cluster as France and the EU formally attribute it and sanction AO AST and NPP Gamma

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

attributed activity

Where this entity is cited

  • deep-dive2
  • updates1
  • weekly-top-stories1

Source distribution

  • bleepingcomputer.com2 (13%)
  • bacs.admin.ch1 (7%)
  • blog.talosintelligence.com1 (7%)
  • cert.pl1 (7%)
  • cert.ssi.gouv.fr1 (7%)
  • cms.news.admin.ch1 (7%)
  • cyber.gouv.fr1 (7%)
  • defense.gouv.fr1 (7%)
  • other6 (40%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (15)

Entries about Static Tundra (4)

2026-08-24 · view entry permalink →

HIGHNATOA2

Switzerland's federal cyber authority reports the public sector as still the largest share of mandatory critical-infrastructure notifications, and devotes its half-year report to two things a Swiss defender can act on: the anatomy of the Polish energy sabotage, and a crypto-theft playbook that recruits its victims on LinkedIn

Switzerland's Bundesamt für Cybersicherheit (BACS) published Halbjahresbericht 2026/I — its semi-annual report on the cyber threat landscape in Switzerland and internationally — on 2026-08-24 (BACS, 2026-08-24). Two numbers frame it. Voluntary reports fell to 27,128 for January–June 2026 against 35,727 in H1 2025, with fraud (10,759), phishing (8,877) and spam (3,965) the most-registered categories. Separately, 200 mandatory reports were processed under the critical-infrastructure notification duty in force since 1 April 2025 — and their sector split is the finding this constituency should read first: the public sector and IT/telecommunications continue to be the most frequent reporters, at 19.4% and 18.6% respectively — BACS's own word is "weiterhin", continuing, so this is a persistent ranking rather than a new development. Among those mandatory reports, unauthorised system access (hacking) is the most-reported attack type at just under 26%, which BACS says consists largely of email accounts compromised through successful phishing and then reused to run further phishing and fraud against others; credential theft follows at 13.5%, with DDoS and data exfiltration tied at 12.7% each, and ransomware in roughly 8% of cases.

Three categories fell sharply, and exactly one of them is given a cause. Reports of fraudulent threatening calls made in the name of authorities fell 64% year on year to 3,817, and BACS credits the tightening of the telecommunications services ordinance against call spoofing — noting the measures likely took effect before they formally came into force. Advertising for online investment fraud fell 89% to 387 and CEO fraud 57% to 258; the report records those two as declines without attributing either to a cause, so neither should be read as evidence that a control worked. Set against that, BACS records attackers using AI systematically to produce tailored, personalised content credibly, including one CEO-fraud case in the period that used a cloned voice of the target's superior to push staff toward fraudulent transfers, and romance-scam identities built with AI-generated images, imitated voices and increasingly deepfake-supported video calls.

On initial access BACS reports no Switzerland-specific tradecraft, only global patterns — and three of them are worth a hunt. Malware by email remains a principal vector with fake invoices the commonest pretext; ClickFix, where the victim is induced to run the malicious command themselves, remains widespread, as does the fake-software-update variant, illustrated by a campaign that told targets to install a Zoom update to join a meeting. In the reporting period BACS identified at least 191 Swiss WordPress sites that attackers had compromised and seeded with malicious JavaScript, which makes a visitor's browser fetch further malicious code automatically — with blockchains increasingly used to host and distribute that code. And in a multi-stage case BACS describes, an employee's business mailbox was buried under email bombing, after which the attackers contacted the victim over Microsoft Teams posing as IT help-desk staff, talked them into granting remote access, and installed malware disguised as an update, citing Unit 42's write-up of the pattern. That is the same delivery chain this pipeline covers today from Expel's SynkLoader case, which is worth noting because a Swiss authority independently placing the pattern in its own caseload raises it from one vendor's incident to an expected local vector. BACS also records several large software-supply-chain compromises with global reach in the period, in which the compromise of widely used open-source projects spread credential-stealing software broadly and Swiss organisations were among those affected — citing the Trivy tag compromise, ground this store already holds. Elsewhere it notes attackers defeating multi-factor authentication through intercepted session tokens, device-code phishing and reverse proxies, and an international shift away from technical complexity toward the principle "log in, not break in": rather than intruding without authorisation, attackers increasingly try to obtain legitimate credentials and use them.

The Poland case study — where basic controls, not advanced defence, were the missing layer. The report's second chapter is a full anatomy of the coordinated wave of 29 December 2025 against Polish energy assets, an incident this store tracks. The Polish CERT's public attribution is of the attack infrastructure to Static Tundra, a suspected Russian state actor previously linked to energy-sector espionage — infrastructure, not the operation itself — and BACS then extends that with its own hedge, recording the Poland incident as the first publicly documented sabotage operation in which the group was apparently involved. Targets ran from 30 wind and photovoltaic parks through a large combined heat and power plant supplying heat to around 500,000 people, to a manufacturing company. The attackers went for the distributed control systems used to operate infrastructure remotely rather than the turbines and generators themselves, and at the renewables sites concentrated on the grid connection point — effectively the operator's digital control room for steering and remote monitoring.

How they got in is the part that should change a Swiss operator's priorities. Alongside exploitation of known unpatched vulnerabilities, remote-access points were exposed directly to the internet without multi-factor authentication, the same passwords were reused across multiple devices, and in several cases devices still carried the manufacturer's factory default passwords ("auf den Geräten noch die werkseitigen Standardpasswörter des Herstellers eingestellt" — in several cases the devices still had the manufacturer's factory default passwords set). Firewalls, servers and a range of OT devices were affected: controllers, remote terminal units reached over SSH, intelligent electronic devices such as protection and control relays, and Windows-based HMI workstations running a SCADA suite. Some of those systems handed the attackers system-administrator rights and so unrestricted control. Destruction was then achieved several ways: corrupting controller firmware so devices hung in an endless reboot loop, deleting operating-system files so they could not boot, and resetting other components to factory settings while changing their network configuration so they became unreachable — with wiper malware additionally deployed on the Windows control machines.

The heat plant was hit entirely through the office IT network without touching its industrial control systems, via the perimeter firewall using accounts again unprotected by MFA. There the actors took their time: over roughly a month they mapped which systems could reach the plant's industrial controls — enumerating processes, network connections, routing tables and the ARP cache, and probing file systems on machines whose names contained "scada" — then quietly stole credentials to impersonate legitimate users, including an attempt to dump the LSASS process, a forged Kerberos ticket built with a public tool, and a dump of the entire Active Directory database via ntds.dit. On 29 December they pushed the DynoWiper malware to workstations using Group Policy Objects, the same mechanism administrators use to deploy software centrally — and an endpoint detection and response product caught and blocked it before it did broad damage. A slightly modified build failed too, as did direct overwriting of server disks and manipulation of the storage system's RAID configuration. At the third victim, a manufacturer that appears to have been chosen opportunistically, the attackers did not have to defeat the perimeter firewall at all: its configuration including passwords had been stolen in an earlier, unrelated incident and was freely available on a criminal forum. Once in, they established durable access by planting automated routines on the firewall that periodically retrieved valid credentials and weakened account security settings — including disabling MFA — piping the output to a Slack channel for convenience, then moved laterally over an SSL VPN tunnel using penetration-testing tooling and deployed a second wiper, LazyWiper, again through Group Policy from a network share. In all three cases stolen credentials drove lateral movement, and — the detail most worth carrying — the same credentials were used to reach the victims' on-premises and cloud services including Exchange, Teams and SharePoint, where the actors searched specifically for files and mail concerning technical operations and ICS, OT and SCADA systems. BACS notes the campaign required substantial manual effort rather than the AI and automation the wider trend points to, and reads the timing as an opportunistic capability demonstration — signalling — rather than a strategically chosen moment, precisely because the exploited weaknesses were so basic. Its conclusion is explicit: basic cybersecurity measures, not advanced defensive technology, would have been the key to preventing these attacks — strong unique passwords, consistent MFA, network segmentation and timely patching.

For Switzerland specifically, BACS argues the exposure is not symmetrical. Large grid connection points here are for the most part better isolated than Poland's, but that assessment excludes the large number of smaller private feed-in installations, which are permanently connected to the internet and to the manufacturer's cloud — and it cites the National Test Institute for Cybersecurity's study of energy-management systems for private photovoltaic installations as establishing the resulting dependencies and broad attack surface. It also draws a supply-chain lesson from a March 2026 case in which Iran-linked attackers claimed to have wiped all reachable devices of a US medical-device manufacturer by factory reset: the victim was not the most strategically relevant target available, but the attack carried a public message — and Swiss business customers of that manufacturer were affected downstream, unable to place their next order through established channels.

The Dream Job playbook, measured in Swiss cases. The third chapter documents crypto theft run through a staged recruitment process against Swiss individuals and companies in the crypto, blockchain and Web3 sectors, which BACS assesses resembles patterns other authorities have attributed to actors operating on behalf of the DPRK — the campaigns tracked publicly as Operation Dream Job and, in its newer variant, Contagious Interview. The actors first identify people in key positions with privileged access to systems and funds — an independent software developer, or the founder of a crypto organisation — then profile the target's preferred technology stack, personal interests, investment intentions, access to company funds and wallet size. The approach comes on LinkedIn from a well-connected, polished headhunter with an offer that is hard to refuse: to earn a generous six-figure salary a developer need only run a test application and fix its bugs, which means fetching code from a repository that silently compromises their system. For less technical targets the lure is tailored differently — a venture capitalist hunting the next unicorn, or a well-paid operations-manager role for a back-office employee — and runs through a video interview on genuine conferencing software where the connection appears to drop, the interviewer persuasively proposes a quick hotfix to repair the tool, and the "fix" pulls trojanised software dependencies or downloads a second-stage payload named OtterCookie or BeaverTail. Those payloads execute only in memory, harvest credentials, tokens and wallet keys to the operators' infrastructure, and often lead to a bespoke DPRK backdoor for persistence; BACS notes no case has been reported of any other known actor using those specific samples. The attackers then attempt lateral movement into the victim's employer network to steal further assets.

In Switzerland such reports have risen steadily over five years to more than 20 confirmed cases, with victims often connected to the crypto industry in roles from engineer to executive, and losses running "von einigen Tausend bis hin zu rund 60 Millionen Schweizer Franken" (from a few thousand up to around 60 million Swiss francs). BACS is contacted weekly by targets who spot the approach in time — and received just as many reports from victims who realised only afterwards. It expects the true figure to be considerably higher, and names the reason as a structural one rather than a technical one: shame, information asymmetry and lack of awareness. The asymmetry it stresses is between employee and employer. Staff have little incentive to tell their employer about a security breach arising from a job search, which buys the attackers time to work laterally — and BACS has seen cases where several employees of the same company were approached, on the reasonable assumption that they would not compare notes with each other.

Triage: for the Dream Job chain the discriminator is sequence and endpoint role, not the sample. A developer workstation fetching and building an unfamiliar external repository is routine; the same host doing so shortly after an inbound recruiter contact, followed by an in-memory payload reaching out to previously unseen infrastructure and then authenticating to internal systems, is the chain. For the conferencing variant, the tell is a user-run "hotfix" during or just after a video call on legitimate software — a genuine conferencing client updates itself through its own updater and does not ask a user to paste or execute a repair command. BACS's own reporting-behaviour finding is the operational corollary: because the initial compromise arrives through a private job search, the employer usually learns late or not at all, so make it explicitly safe and expected for staff to report a suspicious recruitment approach without implying fault — the report's evidence is that several employees at one company were approached and none compared notes.

auf den Geräten noch die werkseitigen Standardpasswörter des Herstellers eingestellt.

Höhe von einigen Tausend bis hin zu rund 60 Millionen Schweizer Franken.

Statt unautorisiert in ein System einzudringen, versuchen die Angreifer zunehmend,

Bundesamt für Cybersicherheit (BACS)
annual-report24 Aug 09:10Zsingle-source · national CERTOpen finding ↗

2026-07-19 · view entry permalink →

HIGHexploitedNATOA1

Russian state-nexus pre-positioning against European critical infrastructure reached a new attribution-and-consequence threshold this week — router hijacking, the Turla espionage cluster, the Poland grid attack and camera surveillance all named on the same day the EU and UK imposed their first joint cyber-sanctions

If you did nothing this week: the internet-facing routers and IP cameras in your estate are exactly the collection surface a 19-agency advisory and Dutch intelligence just documented Russian state actors harvesting at scale — default or weak SNMP community strings, unpatched Cisco Smart Install, and default-credential cameras are being enumerated and read now, not hypothetically.

The week's Russian-state thread was not one disclosure but four landing together, which is itself the signal. The router-hijacking advisory describes FSB Centre 16 (Static Tundra / Berserk Bear) doing something deliberately unglamorous at scale: "The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication" and pair that with the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to pull device configurations out of energy, government, telecom, finance and healthcare networks (joint advisory, 2026-07-13). The consequence side arrived the same day: "The UK together with EU member states has also today formally attributed the December 2025 attack on Poland's energy grid to Russia's FSB Centre 16" (NCSC-UK, 2026-07-13), with the FCDO framing that a "reckless attack ... could have caused 500,000 citizens to lose electricity in the depths of winter" and the EU and UK issuing their first joint cyber-sanctions package (UK Government, 2026-07-13). France's ANSSI simultaneously attributed the Turla espionage set (SecretBlizzard) to the same FSB 16th Centre in CERTFR-2026-CTI-005, with the EU sanctioning 9 individuals and 4 organisations and the UK 24 (CERT-FR, 2026-07-13).

Running underneath all of it, Dutch intelligence disclosed that "Russian actors had compromised 'a small number of cameras' on routes for military shipments to Ukraine" — internet-connected cameras reachable because of default passwords and outdated firmware — a physical-surveillance use of the same exposed-device class the router advisory addresses (NL Times, 2026-07-11).

The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication

NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries) 2026-07-13

The UK together with EU member states has also today formally attributed the December 2025 attack on Poland's energy grid to Russia's FSB Centre 16.

NCSC-UK 2026-07-13

Dutch intelligence services disclosed Friday that Russian actors had compromised “a small number of cameras” on routes for military shipments to Ukraine.

NL Times (ANP) 2026-07-11

Builds on: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes

synthesis19 Jul 23:42Zmulti-sourceOpen finding ↗

2026-07-13 · view entry permalink →

NOTABLEupdateNATOA2

France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions

UPDATE · originally covered FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions (2026-07-13)

The morning entry covered the 19-agency Static Tundra/Berserk Bear advisory (SNMP and Cisco Smart Install router hijacking) and the UK/EU attribution of the December 2025 Polish grid sabotage. This delta covers the sibling FSB Centre 16 cluster — Turla — which France and the EU formally attributed the same day. France's Cyber Crisis Coordination Centre (C4 — ANSSI, COMCYBER, DGA, DGSE, DGSI and the Ministry for Europe and Foreign Affairs) and the EU High Representative jointly attributed the Turla intrusion set to the FSB's 16th Centre on 2026-07-13, publishing CERT-FR's technical report CERTFR-2026-CTI-005 alongside formal French and EU attribution statements (CERT-FR, 2026-07-13; ANSSI, 2026-07-13). France's COMCYBER describes Turla as an FSB 16th Centre attack mode (mode opératoire) used for intelligence-gathering since at least 2004 (COMCYBER, 2026-07-13). The 16th Centre is the parent unit behind both this Turla/Secret Blizzard espionage set and the Static Tundra/Berserk Bear router-hijacking cluster covered this morning — the EU-sanctions reporting describes the 16th Centre as controlling groups including Turla (heise online, 2026-07-13).

ANSSI documents French Turla victims including Ministry of Armed Forces webmail accounts compromised since 2017, the network of the French Embassy in Moscow (2018), a justice-sector personnel-training host (2019) and an advanced-technology company (2025), plus opportunistic intermediary compromises across varied sectors between 2019 and 2025 used as relay infrastructure (CERT-FR, 2026-07-13). The initial-access tradecraft combines spearphishing and watering-hole attacks that lure targets into downloading malicious files masquerading as legitimate software, plus exploitation of vulnerabilities in webmail/messaging services, browsers, business applications and web servers; the operators favour rented or previously-compromised infrastructure for camouflage (ANSSI, 2026-07-13). In coordination, the EU sanctioned 9 individuals and 4 organisations (entry bans and asset freezes), including the enabler firms Advanced System Technology (AST) and NPP Gamma, and the UK sanctioned 24 individuals and organisations; the EU Council statement names Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland among affected states (heise online, 2026-07-13).

Members of the Cyber Crisis Coordination Centre (C4) have observed the targeting and compromise of French entities using the Turla intrusion set operated by the 16th Centre of the Federal Security Service of the Russian Federation (FSB).

CERT-FR (ANSSI) 2026-07-13

Russian technology companies supporting the intelligence service are also affected. For example, Advanced System Technology (AST) and NPP Gamma will no longer be allowed to do business in the EU in the future.

heise online (citing EU Council statement)
threat13 Jul 20:35Zmulti-sourceOpen finding ↗

Earlier coverage (1)