Key Takeaways
- U.S. officials are warning that Russia-linked state hackers are targeting home and small-office routers.
- The concern is not just device compromise, but use of those routers as proxy infrastructure to hide later activity.
- The advisory points to common or default SNMP credentials on poorly configured devices as a key risk.
What happened
The U.S. government has warned users of home and small-office routers to secure their devices because Russia state hackers continue to compromise them at scale. According to the advisory, the goal is not simply to take over individual routers for their own sake. Instead, compromised devices can be used to obscure malicious activity against sensitive organizations in both the public and private sectors.
The warning was issued by the Cybersecurity and Infrastructure Security Agency and co-issued by governments including Australia, Denmark, New Zealand, and the UK. The advisory says Russian Federal Security Service, or FSB, Center 16 cyber actors are continuing to exploit poorly configured and vulnerable networking devices worldwide.
The groups involved are tracked under multiple names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The reporting also notes that both Russian and Chinese government-linked actors have been compromising routers for years, sometimes in back-and-forth campaigns to take control of devices already seized by the other side.
That long-running activity has led to repeated efforts to clean up botnets and disrupt the proxy networks built from infected routers. The source material describes those efforts as a continuing cycle: governments have issued covert commands at times, and companies such as Google have helped disrupt botnets, but attackers can replace one set of compromised devices with another.
Why it matters
Routers are attractive targets because they sit at the edge of a network, often with less attention than laptops, servers, or phones. In many homes and small offices, the router is installed once and then forgotten. That makes it a useful target for attackers who want persistence without drawing much notice.
The advisory highlights a practical route in: attackers scan IP ranges for devices with active Simple Network Management Protocol, or SNMP, agents that accept common or default authentication credentials. SNMP is used to collect and organize information about managed networking devices and, in some cases, to modify that information in ways that change device behavior.

The warning indicates that poorly configured routers can be abused as part of a larger proxy network. That matters because proxy infrastructure helps attackers route their traffic through innocent-looking devices, making the activity harder to trace back to the real source. For defenders, that means a router compromise is not only a device problem, but also a network-trust problem.
The point for ordinary users is simple: routers are not invisible background hardware anymore. A device that is weakly configured, still using default credentials, or exposed in the wrong way can become part of a broader campaign. For IT teams, especially in small organizations, the warning is a reminder that edge devices need the same maintenance mindset as endpoints and servers.
The broader pattern also shows why this category of threat is hard to stamp out. The source material compares the effort to a whack-a-mole exercise. Even when one botnet is disrupted, attackers can re-enroll fresh devices and continue using the same basic model.
What to watch
The immediate thing to watch is whether the advisory leads more home users and small businesses to review router settings, especially SNMP exposure and credential hygiene. The source does not provide a step-by-step mitigation list, but it clearly points to common or default authentication as a key weakness.
It is also worth watching how disruptive the cleanup efforts are over time. The reporting suggests governments and private companies have had some success against existing botnets, but those wins may be temporary if vulnerable routers remain widely available.
A final question is whether this warning shifts attention toward consumer networking gear as a persistent security problem rather than a one-time setup chore. If so, routers could receive more of the scrutiny already common for other internet-connected devices. For now, the message from the advisory is blunt: overlooked networking gear can still be a valuable target for sophisticated state-backed operators, and that makes basic router security more important than ever.



