Skip to main content

UK and US issue warning about APT28 actors exploiting poorly maintained Cisco routers

Joint advisory calls on organisations to secure devices to prevent network attacks.

Image credit: istock.com/Victor Metelskiy

UK and US agencies have today (Tuesday) issued a joint advisory to help organisations counter malicious activity used by Russian cyber actors to exploit poorly maintained Cisco routers.

APT28 – a threat group attributed to Russia’s military intelligence service the GRU – has been observed taking advantage of poorly configured networks and exploiting a known vulnerability to deploy malware and access Cisco routers worldwide.

In 2021, a series of attacks was carried out against a small number of organisations based in Europe, US government institutions and around 250 Ukrainian victims for reconnaissance purposes, with Jaguar Tooth malware then deployed against some targeted devices to enable unauthenticated access.

The advisory, issued by the National Cyber Security Centre (NCSC) – a part of GCHQ –  and the US National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), strongly recommends organisations follow the mitigation advice to defend against this activity.

This includes applying the security update released by Cisco to address the vulnerability CVE-2017-6742.

The advisory has been published on the eve of CYBERUK 2023, the UK’s flagship cyber security conference, which attracts experts from across the globe, held for the first time this year in Northern Ireland.

Paul Chichester, NCSC Director of Operations, said:

“This malicious activity by APT28 presents a serious threat to organisations, and the UK and our US partners are committed to raising awareness of the tactics and techniques being deployed.

“We strongly encourage network defenders to ensure the latest security updates are applied to their routers and to follow the other mitigation steps outlined in the advisory to prevent compromise.”

Eric Goldstein, Executive Assistant Director for Cybersecurity, CISA said:

“With our partners at the NCSC, FBI, and NSA, CISA is urgently focused on sharing actionable information to help organizations identify and mitigate risks posed by sophisticated threat actors like APT28. We encourage all organizations to prioritize adoption of mitigations outlined in our joint advisory and take urgent actions to reduce the likelihood of damaging intrusions.”

In addition to applying the security update, it also encourages organisations to:

UK organisations should report suspected compromises to the NCSC. Cisco has published a blog post about the activity. 

Read the full advisory and associated malware analysis report