Also known as: Energetic Bear, BERSERK BEAR, techniques, victimology, FSB Center 16, CVE-2018-0171, ALLANITE, CASTLE, DYMALLOY, TG-4192, Dragonfly, Crouching Yeti, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, Palmetto Fusion, Allanite, Operator Panda
Static Tundra emerged as a Russian‑state sponsored threat actor affiliated with FSB Center 16 that has been active for over a decade. Its attack lifecycle centers on the exploitation of unpatched Cisco Smart Install (CVE-2018-0171) to compromise edge routers and switches, followed by the implantation of custom firmware such as SYNful Knock to preserve long‑term control. The group uses default or stolen SNMP community strings to read, modify, and copy configuration data and often establishes TFTP/FTP servers for exfiltration of device configurations. Persistence is further achieved through creation of privileged local accounts, modification of TACACS+ settings, and the deployment of GRE tunnels that redirect network traffic for clandestine command‑and‑control. Static Tundra’s operations span both espionage—collecting operational data from industrial control systems—and sabotage, exemplified by coordinated destruction of Polish wind farms and solar plants via wiper malware in late 2025. The group frequently targets sectors that provide strategic value: telecommunications, higher‑education institutions, manufacturing facilities, and critical infrastructure such as energy, healthcare, finance, and maritime operations. Its campaigns have shown adaptability across multiple geographic footprints—Poland, Ukraine, Russia, the United States, the United Kingdom, China, and the Middle East—indicating a broad geopolitical agenda aligned with Russian strategic objectives. Static Tundra’s technical repertoire demonstrates a high degree of sophistication, including exploitation of vendor‑specific firmware vulnerabilities, native SNMP manipulation for lateral movement, and covert exfiltration channels. The group also exhibits behavioral patterns consistent with long‑term monitoring: it maintains persistent footholds on compromised infrastructure for extended periods while subtly evading detection through ACL tampering, proxy use, and obfuscated command execution.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Static Tundra is a long‑operated Russian FSB‑centered cyber‑espionage and sabotage group that has leveraged the Smart Install CVE‑2018‑0171 flaw in Cisco networking gear to gain persistent access across critical infrastructure, telecommunications, education, and manufacturing sectors. Recent activity culminated in destructive attacks on Poland’s energy grid, deploying wiper malware such as DynoWiper and LazyWiper while exploiting FortiGate perimeter devices with stolen or default credentials.
Goals & Targeting
The actor’s primary objective appears to be dual‑faceted—firstly accruing actionable intelligence from critical sectors that support state interests, and secondarily undermining the operational resilience of politically sensitive targets. By infiltrating telecommunications and industrial control networks, Static Tundra can gather network topology, service credentials, and configuration details, thereby enabling future sabotage or data exfiltration. The geographic focus on Ukrainian, Polish, and other European entities during the ongoing Russo‑Ukrainian conflict reflects a strategy of geopolitical influence through infrastructure destabilization.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Static Tundra’s known campaigns exhibit a blend of espionage and sabotage. Early attacks focused on infiltrating Cisco edge devices in telecom, higher‑education, and manufacturing networks via the Smart Install flaw; more recent operations have included outright destructive payloads against Poland’s renewable energy sector following the 2025 blackout events. The group operates at an accelerated tempo during periods of geopolitical tension—most notably the Russia‑Ukraine conflict—and selects high‑visibility public utilities to maximize strategic impact. Victims span critical infrastructure, energy, maritime, construction, and private defense entities across Europe, the United States, China, the Middle East, and the UK, demonstrating operational flexibility and an intention to pressure host nations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The association of Static Tundra with Russian FSB Center 16 and its use of the Smart Install CVE‑2018‑0171 exploit is supported by multiple independent reports, providing a high degree of confidence in these technical footprints. The attribution to sabotage operations—particularly the December 2025 Poland energy grid attacks—derives from publicly disclosed incident analyses, yielding moderate confidence that these events are linked. However, some gaps remain regarding the actor’s broader strategic motivations, detailed timelines for early activity, and full inventory of malware families employed beyond the known wipers, limiting completeness of the threat profile.
No campaigns linked yet.
No observed data linked yet.
27
Techniques
46
Tools
0
Campaigns
68
IOCs
0
Observed Data
12
Tactics