Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    US seizes over 1,000 websites in FIFA World Cup piracy crackdown

    July 21, 2026

    Infosec News Nuggets — July 21, 2026 – AboutDFIR

    July 21, 2026

    Microsoft shares manual fix for WSUS sync delays and timeouts

    July 21, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Finding the Routers Energetic Bear Is Looking For | Blog
    News

    Finding the Routers Energetic Bear Is Looking For | Blog

    adminBy adminJuly 21, 2026No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    On July 9, 2026, the National Security Agency (NSA) and 18 other domestic and international cybersecurity agencies jointly published Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting, an advisory detailing Cisco-focused activity attributed to Energetic Bear, a threat actor linked to Russia’s Federal Security Service (FSB).

    Energetic Bear, also known as Dragonfly, Ghost Blizzard, and Crouching Yeti, is a state-backed actor that has been active since at least 2010. Known for targeting the energy sector, this sophisticated group has historically relied on well-known n-day vulnerabilities in client-side attacks, including CVE-2012-1723 in the Java Runtime Environment, CVE-2012-4792 in Internet Explorer, and CVE-2011-0611 in Adobe Flash Player.

    The activity described in the NSA advisory is not sophisticated. Rather than exploiting users, Energetic Bear scans the internet for exposed Cisco SNMP services, guesses weak or default community strings, and uses legitimate configuration-copy functionality to retrieve running configurations. Metasploit has included a module implementing this technique since at least 2010.

    Running configurations can expose credentials, internal addressing, routing relationships, access-control rules, and other details useful for expanding access into the victim network. Metasploit even includes a separate module for importing and parsing stolen Cisco IOS configurations. The offensive value of these files has been understood for a long time.

    The problem isn’t understanding why Energetic Bear is doing this. It’s identifying the systems that remain vulnerable to it.

    VulnCheck Target Intelligence approaches the internet with the same basic question Energetic Bear asks: where are the vulnerable systems? For this advisory, that becomes even more specific: which Cisco devices are exposing SNMP to the public internet?

    A single Target Intelligence API query surfaces Cisco devices observed responding to SNMP on the public internet:

    https://api.vulncheck.com/v3/index/target-intel?protocol=snmp&vendor=cisco

    At the time of our analysis, the query returned thousands of Cisco SNMP endpoints. Given Energetic Bear’s continued success, the result is not especially surprising.

    The example below shows a Cisco C800 series router running IOS 15.3(3)M6, a software release that reached its last date of support more than five years ago. The system is publicly reachable over SNMPv2c and responds to the default public community string. Target Intelligence also maps the observed software to associated vulnerabilities and enriches the device with network ownership and location data.

    The associated CVE array was omitted for brevity.

    {
      "ip": "94.77.200.34",
      "hostname": "94-77-200-34.static.go.com.sa",
      "port": 161,
      "timestamp": "2026-07-09T01:30:34.049Z",
      "protocol": "snmp",
      "cpe": [
        "cpe:2.3:o:cisco:ios:15.3:*:*:*:*:*:*:*"
      ],
      "cve": [
        "truncated"
      ],
      "vendor": [
        "cisco"
      ],
      "product": [
        "ios"
      ],
      "version": [
        "15.3"
      ],
      "asn": "AS47794",
      "as_name": "Etihad GO Company For communications",
      "as_domain": "go.com.sa",
      "country": "Saudi Arabia",
      "country_code": "SA",
      "metadata": {
        "community": "public",
        "engine_enterprise_id": 9,
        "snmp_version": "v2c",
        "sys_descr": "Cisco IOS Software, C800 Software (C800-UNIVERSALK9-M), Version 15.3(3)M6, RELEASE SOFTWARE (fc1)\r\nTechnical Support: http://www.cisco.com/techsupport\r\nCopyright (c) 1986-2015 by Cisco Systems, Inc.\r\nCompiled Tue 04-Aug-15 05:50 by prod_rel_team",
        "sys_object_id": "1.3.6.1.4.1.9.1.1852"
      }
    }
    

    This is exactly the kind of externally exposed device Energetic Bear is looking for.

    The advisory also identifies two Cisco vulnerabilities used by Energetic Bear.

    The first, CVE-2018-0171, has repeatedly appeared in state-sponsored activity. A similar 2025 joint advisory, Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System, also documented its use by PRC state-sponsored actors associated with Salt Typhoon.

    The second, CVE-2008-4128, is old enough that defenders might reasonably assume affected systems have disappeared from the internet. Target Intelligence suggests otherwise.

    CVE-2008-4128 in the UI

    At the time of writing, a simple query returned hundreds of observed systems whose detected software mapped to CVE-2008-4128:

    https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2008-4128

    One result is a Cisco 1841 router in Venezuela running IOS 12.4(1c), software compiled in October 2005. Target Intelligence identifies the system as internet-exposed, maps its detected software to CVE-2008-4128, and provides network ownership and location context users can use to investigate further.

    Additional mapped CVEs were omitted for brevity.

    {
      "ip": "200.109.233.234",
      "hostname": "200.109.233-234.cnt-02.rai.cantv.net",
      "port": 161,
      "timestamp": "2026-07-09T03:01:14.655Z",
      "protocol": "snmp",
      "cpe": [
        "cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
      ],
      "cve": [
        "CVE-2008-4128"
      ],
      "vendor": [
        "cisco"
      ],
      "product": [
        "ios"
      ],
      "version": [
        "12.4"
      ],
      "asn": "AS8048",
      "as_name": "CANTV Servicios, Venezuela",
      "as_domain": "cantv.com.ve",
      "country": "Venezuela",
      "country_code": "VE",
      "metadata": {
        "community": "public",
        "engine_enterprise_id": 9,
        "snmp_version": "v2c",
        "sys_descr": "Cisco IOS Software, 1841 Software (C1841-IPBASE-M), Version 12.4(1c), RELEASE SOFTWARE (fc1)\r\nCopyright (c) 1986-2005 by Cisco Systems, Inc.\r\nCompiled Tue 25-Oct-05 17:10 by evmiller",
        "sys_object_id": "1.3.6.1.4.1.9.1.620"
      }
    }
    

    The advisory tells organizations what to fix, but that assumes they already know which systems are exposed. Many clearly do not. Internet exposure data has existed for years, yet translating that data into vulnerability context and applying it to a specific advisory can still require significant expertise or a mature exposure management program.

    That is the gap VulnCheck Target Intelligence is intended to close. Defenders can move directly from an advisory to a simple query for the affected protocol, vendor, or CVE and surface the systems that warrant investigation. Advisories describe the risk. Accessible, vulnerability-aware exposure data makes the guidance actionable.

    VulnCheck empowers organizations to transcend the challenges of vulnerability prioritization. Our suite of solutions provides product managers, PSIRT teams, and threat hunters with the tools required for accelerated, high-precision operations and infinite efficiency.

    Recognizing the industry-wide necessity for superior data velocity and accuracy, we deliver high-fidelity insights to the market. We remain committed to surfacing critical intelligence on vulnerability exploitation and emerging trends, leveraging our unique dataset to support the practitioner community.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSonicWall SMA1000 flaws exploited as zero-days to push custom malware
    Next Article Microsoft shares manual fix for WSUS sync delays and timeouts
    admin
    • Website

    Related Posts

    News

    US seizes over 1,000 websites in FIFA World Cup piracy crackdown

    July 21, 2026
    News

    Infosec News Nuggets — July 21, 2026 – AboutDFIR

    July 21, 2026
    News

    Microsoft shares manual fix for WSUS sync delays and timeouts

    July 21, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202635 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202635 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    US seizes over 1,000 websites in FIFA World Cup piracy crackdown

    July 21, 2026

    Infosec News Nuggets — July 21, 2026 – AboutDFIR

    July 21, 2026

    Microsoft shares manual fix for WSUS sync delays and timeouts

    July 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.