Russian state hackers exploiting weak routers across healthcare

Advertisement

The National Security Agency, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation (FBI) and 15 allied agencies issued a joint advisory in July on a Russian FSB unit exploiting poorly configured routers worldwide.

The unit, known as Center 16 and also tracked as Berserk Bear, Energetic Bear and Static Tundra, has spent more than a decade opportunistically compromising healthcare and public health networks along with energy, communications, financial services and government sectors.

The actors scan for routers running outdated Simple Network Management Protocol (SNMP) authentication, then command exposed devices to copy and exfiltrate their configuration files, typically Trivial File Transfer Protocol (TFTP), to attacker-controlled servers. Some intrusions also exploit known Cisco vulnerabilities or abuse Cisco’s Smart Install feature. Agencies note the techniques overlap with those used by China-linked Salt Typhoon.

Recommended fixes: upgrade to SNMPv3 and disable legacy SNMP versions, disable unused Cisco Smart Install, use strong and securely stored device passwords with multi-factor authentication where possible, block TFTP/SNMP/Smart Install traffic at the network edge, and patch or retire outdated devices.

Health systems, often running sprawling networks with aging equipment, are considered a soft target given the opportunistic, sector-agnostic nature of the scanning.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement