Russian State-Sponsored Hackers Targeting Network Devices, Warns Joint Advisory
A joint advisory from cybersecurity agencies, including the Australian Cyber Security Centre (ACSC), has confirmed a persistent and enduring campaign of malicious cyber activity by Russian state-sponsored actors targeting network devices such as routers and firewalls.
These devices are attractive targets because they sit at the edge of an organisation's network and often receive less attention than servers or endpoints, despite controlling access to internal systems. Compromising them can give attackers a long-term foothold to intercept traffic, pivot deeper into networks, or maintain persistent access without detection.
While the advisory focuses on state-sponsored activity, the underlying weaknesses being exploited—unpatched firmware, weak credentials, and misconfigured devices—are common issues in businesses of all sizes. Australian small businesses using routers, VPNs, or other network appliances should treat this as a reminder to review the security of these often-overlooked devices.