Russian State-Sponsored Hackers Exploit Cisco Flaw to Target US Government Agencies

Russian state-sponsored hacking group APT28, also known as Fancy Bear, has been exploiting a six-year-old vulnerability in Cisco routers to carry out surveillance and deploy malware

Russian state-sponsored hacking group APT28, also known as Fancy Bear, has been exploiting a six-year-old vulnerability in Cisco routers to carry out surveillance and deploy malware, according to a joint advisory by the U.S. cybersecurity agency CISA, the FBI, the NSA, and the U.K.’s National Cyber Security Center. The group is aiming at European organizations and US government institutions by exploiting a remotely exploitable vulnerability patched by Cisco in 2017. The hackers are also targeting Ukrainian victims.

The hackers are using a custom-built malware called “Jaguar Tooth,” which is designed to infect unpatched routers. By scanning for internet-facing Cisco routers using default or easy-to-guess SNMP community string, the threat actors can exploit the Simple Network Management Protocol (SNMP), allowing them to remotely access and configure routers without a username or password. The malware exfiltrates information from the router and provides stealthy backdoor access to the device.

The campaign is part of a broader trend of sophisticated adversaries targeting networking infrastructure to advance espionage objectives or pre-position for future destructive activity. Cisco Talos, a threat intelligence team at Cisco, is deeply concerned by an increase in the rate of high-sophistication attacks on network infrastructure, which state-sponsored actors globally are targeting. China has also been spotted attacking network equipment in several campaigns, according to Olney.

It is not yet clear how many organizations have been affected by APT28’s exploitation of the Cisco vulnerability. However, the US and UK government agencies are warning that this is a serious and ongoing threat. Network administrators should ensure that they apply the latest security patches to all routers and use strong passwords to prevent unauthorized access to their networks. Organizations should also consider implementing security solutions that provide advanced protection for their network infrastructure.

Don’t Stop Here

More To Explore

solar eclipse eclipse solar eclipse 2024 solar eclipse 2023 eclipse 2024 eclipse 2023 2023 eclipse 2023 solar eclipse april 8 2024 eclipse 2024 total eclipse 2023 solar eclipses 2024 sun eclipse eclipse april 8 2024 eclipse lunar eclipse eclipse of the sun 2024 eclipse solar eclipse eclipse2023 lunar eclipses solar and eclipse solar eclipse solar eclipse solar solar eclipse solar sun eclipse total eclipse in 2024 total eclipse 2024 total solar eclipse 2024 next solar eclipse total eclipse next eclipse total solar eclipse april 2024 eclipse annular solar eclipse annular eclipse 2023 lunar eclipse 2023 annular eclipse eclipse april 2024 april 2024 solar eclipse solar eclipse april 2024 annular solar eclipse 2023 eclipse today 2023 annular eclipse total eclipse of the sun 2024 sun eclipse 2024 totality eclipse 2024 total eclipse april 2024 8 april 2024 eclipse lunar penumbral eclipse october 2023 eclipse of 2024 eclipse of sun today eclipse penumbral eclipse timer full eclipse of the moon lunar eclipses 2023 next eclipse of the sun solaire eclipse solar eclipse of april 20 2023 solar eclipse of october 14 2023 solar eclipse today solar v lunar eclipse sun eclipse next total solar eclipse in 2024 upcoming sun eclipse sun eclipse next total solar eclipse eclipse 2022 great american eclipse 2024 total solar eclipse 2023 total eclipse 2023 next eclipse 2023 full solar eclipse 2024 full eclipse 2024 upcoming solar eclipse full solar eclipse next total eclipse eclipse april 2023 sun eclipse 2023 iso 12312 2 next eclipse 2024 next full solar eclipse total lunar eclipse april eclipse 2024 next solar eclipse 2023 future solar eclipses eclipse in 2024 solar and lunar eclipse full eclipse 2023 2023 total solar eclipse 1993 eclipse 2017 eclipse 2017 solar eclipse 2017 total solar eclipse 2019 eclipse 2022 solar eclipse 2024 solar eclipse best viewing april 20 eclipse april 8 2024 solar eclipse april 8 2024 total solar eclipse april eclipse 2023 april solar eclipse 2024 eclipse 1994

Experience the Solar Eclipse with The Eclipse App: Your Ultimate Companion

An innovative app, tailored to enhance your observation of the total solar eclipse on April 8, 2024, has risen to prominence on the App Store. Titled simply “The Eclipse App,” it has amassed over 140,000 lifetime downloads on both iOS and Android platforms. This app serves as a comprehensive tool for experiencing the celestial event, providing features such as cloud cover forecasts, precise timing for totality at your specific location, and details on local events, parks, and viewing sites in your vicinity.

Twitter Introduces Payments for Verified Creators' Advertisements in Replies, Elon Musk Announces

Brazil Investigates Elon Musk Over X Dispute

Brazil has launched an investigation into Elon Musk over potential obstruction of justice following X’s reversal of a decision to block certain profiles in the country.