ADVERTISEMENT

US puts $10M bounty on three Russians accused of attacking critical infrastructure

News Express |6th Sep 2025 | 147
US puts $10M bounty on three Russians accused of attacking critical infrastructure




The US State Department has put a $10 million bounty on the heads of three Russians accused of being intelligence agents hacking America's critical infrastructure - primarily via old Cisco kit, it seems.

The alert directly connects them to reports of the Russian Federal Security Service's (FSB) Center 16 - aka Berserk Bear - accused of using a flaw (CVE-2018-0171) Cisco patched in 2018, but attackers recently exploited it in the Salt Typhoon hacking campaign, which the FBI warns stole data from 'nearly every American,' though investigators attribute the attack to the Chinese.

Prosecutors accuse Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulovof, of targeting over 500 energy companies in 135 countries, using the ancient Cisco flaw to hijack thousands of networking devices to harvest information and install malware.

"The FSB Center 16 unit conducting this activity is known to cybersecurity professionals by several names, including 'Berserk Bear' and 'Dragonfly,' which refer to separate but related cyber activity clusters," Las Vegas police warned last month.

"For over a decade, this unit has compromised networking devices globally, particularly devices accepting legacy unencrypted protocols like SMI and SNMP versions 1 and 2. This unit has also deployed custom tools to certain Cisco devices, such as the malware publicly identified as "SYNful Knock" in 2015."

The Cisco issue is with the Smart Install feature of Cisco IOS and IOS XE software, a CVSS 9.8 flaw, and one that many end-of-life-kit can't patch. But there's plenty of old kit out there doing its job and flying under sysadmins' radar, and it's this kit the trio are accused of infiltrating.

In a 2021 indictment the three Russians allegedly targeted oil and gas firms, nuclear plants, and utility and power transmission companies, seeking to map out internal networks for possible future attacks. In a campaign that began in 2012 they targeted over 3,300 people in 500 organisations around the world, it's claimed.

A few years later the US claims they dug deeper, going after specific key individuals with control of critical networks. Over 3,300 people were targeted in 500 organisations around the world.

One target was the Wolf Creek nuclear power plant in Burlington, Kansas. The suspects, it's said, installed snooping software that harvest login credentials of plant operators and it was only when the nuke site's operators called in the FBI that the intrusion was discovered.

However, as the timeline shows, this was years ago. Quite why the State Department chose this moment to put a sizable bounty on their heads is unclear, since the suspects will presumably avoid US territory and countries that have an extradition treaty with America.

Instead this looks something like a publicity exercise. While it's possible one of the suspects might get caught at an international border if they get sloppy, that's not something the FSB is known to get caught out by.

Cisco has no comment on the matter at time of publication. (The Register)

Comments

Post Comment

Saturday, September 6, 2025 1:02 PM
ADVERTISEMENT

Follow us on

GOCOP Accredited Member

GOCOP Accredited member
logo

NEWS EXPRESS is Nigeria’s leading online newspaper. Published by Africa’s international award-winning journalist, Mr. Isaac Umunna, NEWS EXPRESS is Nigeria’s first truly professional online daily newspaper. It is published from Lagos, Nigeria’s economic and media hub, and has a provision for occasional special print editions. Thanks to our vast network of sources and dedicated team of professional journalists and contributors spread across Nigeria and overseas, NEWS EXPRESS has become synonymous with newsbreaks and exclusive stories from around the world.

Contact

Adetoun Close, Off College Road, Ogba, Ikeja, Lagos State.
+234(0)8098020976, 07013416146, 08066020976
info@newsexpressngr.com

Find us on

Facebook
Twitter

Copyright NewsExpress Nigeria 2025