Technology British Columbia

The US government warns that Russia state hackers are coming after your router

With residential proxies all the rage, CISA urges router users to be vigilant.

The US government warns that Russia state hackers are coming after your router
Text to audio Audio version available

With residential proxies all the rage, CISA urges router users to be vigilant.

The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors. Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers.

Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones. Proxy networks: The go-to tool “Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday.

The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK. The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials.

These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior.

Published
Jul 13, 2026
Updated
Jul 13, 2026
Source
Ars Technica
Category
Technology
Read time
1 min
Key facts

Key facts

SectionTechnology
Open
SourceArs Technica
Open
PublishedJul 13, 2026
UpdatedJul 13, 2026

Why this matters locally

This technology story matters locally because it may affect readers, businesses, commuters, families, or public services in British Columbia.

Local impact

BC Post links this item to British Columbia coverage so readers can follow related city updates, weather, traffic, events, and category news in one place.

Timeline

PublishedJul 13, 2026, 2:03 PMThis story was published by BC Post.
ImportedJul 13, 2026, 6:00 PMThe item entered the BC Post source pipeline.
UpdatedJul 13, 2026, 6:00 PMThe article record or local context was updated.
Transparency

Source and credit

BC Post may summarize, organize, and add local context for reader clarity. Original reporting remains with the listed publisher.

Ars Technica Published Jul 13, 2026 Imported Jul 13, 2026
Read Original Source
Ars Technica Jul 13, 2026
Read Original Source