In a coordinated global warning, cybersecurity agencies from the United States, United Kingdom, Germany, Australia, Denmark, New Zealand, and other nations have issued urgent advisories about Russian state-sponsored hackers systematically compromising home and small office routers. The hacking groups, tracked under names such as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra, are linked to the Russian Federal Security Service (FSB) Center 16. These actors are exploiting poorly configured and vulnerable networking devices to build massive proxy networks that obscure malicious activities against critical infrastructure, government networks, and private sector organizations.

Scope of the Threat

The Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, GCHQ, and Germany's intelligence agency have all warned that Russian hackers have compromised hundreds of thousands of routers across at least 23 states in the US and numerous countries worldwide. The FBI has specifically highlighted that older, unpatched routers—particularly those from TP-Link, Cisco, and other widely used brands—are being hijacked to steal banking logins, credentials, and to conduct espionage. In some cases, the hackers have used compromised routers to pivot into critical infrastructure networks, including energy, water, and transportation sectors.

How the Attacks Work

The hackers employ a multi-stage attack chain. First, they scan for routers with default credentials, outdated firmware, or known vulnerabilities—such as those in TP-Link and Cisco devices. Once inside, they install malware that allows remote control, forming a botnet. These botnets are then used as proxy networks to anonymize further attacks, such as spear-phishing campaigns targeting government employees and critical infrastructure operators. The UK's GCHQ noted that the hackers are using compromised routers as “spying devices” to monitor traffic and steal data.

Historical Context and Escalation

Both Russian and Chinese state-backed hackers have targeted routers for years, often engaging in tug-of-war battles over control of devices. However, this latest campaign marks a significant escalation in scale and coordination. In 2018, the FBI warned that Russian hackers had compromised hundreds of thousands of routers, and the NSA previously urged Americans to reboot their routers to disrupt malware. Despite these efforts, the problem persists, with agencies describing current countermeasures as “whack-a-mole” exercises, as hackers quickly rebuild botnets after takedowns.

Differing Perspectives

While all sources agree on the severity of the threat, there are nuances in framing. US agencies emphasize the risk to critical infrastructure and national security, while UK and European warnings focus on espionage and credential theft. Some outlets, like Wired, criticized the White House for “muddling the message” by conflating different hacking groups. Others, like Ars Technica, highlighted the ongoing struggle between Russian and Chinese hackers for control of compromised routers. Meanwhile, German intelligence specifically pointed to APT28—a unit of Russia's GRU—exploiting TP-Link router flaws, indicating multiple Russian agencies are involved.

Expert Views and Implications

Cybersecurity experts warn that the widespread compromise of routers poses a unique threat because these devices are often neglected by users and ISPs. “Routers are the front door to your network, and if they're compromised, all connected devices are at risk,” said a senior analyst at the National Cybersecurity Alliance. The implications are far-reaching: from personal data theft to disruption of critical services. The New Zealand GCSB boss confirmed that Russian hackers have directly threatened the country's networks, underscoring the global nature of the campaign.

What You Should Do

Agencies recommend immediate actions:

  • Change default router passwords and update firmware to the latest version.
  • Disable remote management and UPnP features if not needed.
  • Reboot routers periodically to disrupt some malware strains.
  • Replace older routers that no longer receive security updates—especially TP-Link models flagged in recent advisories.
  • Consider using a VPN and enabling WPA3 encryption.

Conclusion

The coordinated global advisory signals a new phase in state-sponsored cyber operations. As hackers continue to exploit the weakest links in network security, the onus is on individuals, ISPs, and governments to harden these devices. Without a concerted effort to patch and replace vulnerable routers, the botnet armies will only grow, enabling ever more damaging attacks on the digital infrastructure we all rely on.