Free tools Windows power users keep installed
One-click scans. No signup required.
Amazon Threat Intelligence says misconfigured customer network-edge devices became the main initial-access route in one Russian state-sponsored campaign targeting Western critical infrastructure by 2025, while the campaign’s use of vulnerability exploitation declined. The report describes a shift in emphasis—not an end to vulnerability exploitation, and not evidence that every Russian-linked group prefers misconfigurations.
What Amazon reported—and what it does not establish
In a December 15, 2025 AWS Security Blog report, Amazon Threat Intelligence described sustained targeting of global infrastructure from 2021 through 2025, particularly the energy sector and its supply chain. Amazon assessed with high confidence that the campaign cluster was associated with Russia’s Main Intelligence Directorate (GRU), citing infrastructure overlaps and consistent targeting patterns. That is Amazon’s attribution assessment, not an independently adjudicated finding.
The campaign touched a broad range of internet-facing and online services: enterprise routers, VPN concentrators, remote-access gateways, network-management appliances, collaboration and wiki platforms, and cloud-based project-management systems. Amazon’s central finding was that misconfigured customer edge devices had become the primary initial-access vector by 2025 as exploitation activity declined.
How the campaign’s tactics changed
Amazon’s timeline shows vulnerability exploitation continuing alongside targeting of misconfigured devices. The shift was in emphasis, not a clean break from exploits.
| Period | Activity Amazon reported |
|---|---|
| 2021–2022 | WatchGuard exploitation and targeting of misconfigured devices. |
| 2022–2023 | Confluence exploitation alongside continued targeting of misconfigured devices. |
| 2024 | Veeam exploitation alongside continued targeting of misconfigured devices. |
| 2025 | Sustained targeting of misconfigured customer edge devices, with declining N-day and zero-day exploitation activity. |
Amazon said the tactical change could still support credential harvesting and lateral movement while reducing an actor’s exposure and resource expenditure. The report does not provide a denominator for calculating what share of Russian-linked attacks use misconfigurations, so its campaign finding should not be treated as an industry-wide percentage.
#1 Best Overall
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
How a compromised edge device can lead to further access
Amazon described a sequence involving a customer network-edge device hosted on AWS. The actor compromised the device, used packet-capture capability, obtained credentials, attempted to replay them against victim online services, and sought persistent access for lateral movement. Amazon reported that the credential-replay attempts it discussed were unsuccessful.
There is an important limit to that account: Amazon said it did not directly observe how credentials were extracted. Its assessment that packet capture and traffic analysis enabled credential collection was based on timing, the types of credentials involved, and the actor’s position in the network. The mechanism is therefore an inference, not a directly observed step.
Other Russian-linked activity is separate from Amazon’s campaign
FBI warning about FSB Center 16
A separate FBI public service announcement dated August 20, 2025 addressed activity attributed to Russian FSB Center 16, also associated in cybersecurity reporting with names including Berserk Bear and Dragonfly. The FBI said the actors exploited SNMP and end-of-life networking devices running an unpatched Cisco Smart Install vulnerability, CVE-2018-0171.
Rank #2
- 𝐅𝐮𝐭𝐮𝐫𝐞-𝐑𝐞𝐚𝐝𝐲 𝐖𝐢-𝐅𝐢 𝟕 - Designed with the latest Wi-Fi 7 technology, featuring Multi-Link Operation (MLO), Multi-RUs, and 4K-QAM. Achieve optimized performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, and Samsung Galaxy S24 Ultra.
- 𝟔-𝐒𝐭𝐫𝐞𝐚𝐦, 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝐰𝐢𝐭𝐡 𝟔.𝟓 𝐆𝐛𝐩𝐬 𝐓𝐨𝐭𝐚𝐥 𝐁𝐚𝐧𝐝𝐰𝐢𝐝𝐭𝐡 - Achieve full speeds of up to 5764 Mbps on the 5GHz band and 688 Mbps on the 2.4 GHz band with 6 streams. Enjoy seamless 4K/8K streaming, AR/VR gaming, and incredibly fast downloads/uploads.
- 𝐖𝐢𝐝𝐞 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐰𝐢𝐭𝐡 𝐒𝐭𝐫𝐨𝐧𝐠 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 - Get up to 2,400 sq. ft. max coverage for up to 90 devices at a time. 6x high performance antennas and Beamforming technology, ensures reliable connections for remote workers, gamers, students, and more.
- 𝐔𝐥𝐭𝐫𝐚-𝐅𝐚𝐬𝐭 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐖𝐢𝐫𝐞𝐝 𝐏𝐞𝐫𝐟𝐨𝐫𝐦𝐚𝐧𝐜𝐞 - 1x 2.5 Gbps WAN/LAN port, 1x 2.5 Gbps LAN port and 3x 1 Gbps LAN ports offer high-speed data transmissions.³ Integrate with a multi-gig modem for gigplus internet.
- 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
In the preceding year, the FBI detected collection of configuration files for thousands of networking devices associated with U.S. entities across critical-infrastructure sectors; the announcement did not state an exact count. The FBI also reported that actors modified some configurations to enable unauthorized access and conducted reconnaissance that showed interest in ICS-related protocols and applications. This is a distinct threat cluster and should not be merged with Amazon’s GRU-associated campaign.
Pro-Russia hacktivists targeting operational technology
A May 1, 2024 fact sheet from CISA, the FBI, the NSA, and partner agencies described pro-Russia hacktivists accessing internet-exposed industrial control systems (ICS) and human-machine interfaces (HMIs), including through VNC, factory-default or weak passwords, and remote access without multifactor authentication (MFA).
In early 2024, CISA and the FBI responded to U.S. water and wastewater victims whose HMIs had been manipulated. Actors changed pump and blower settings, disabled alarms, and changed administrator passwords. Some victims experienced minor tank overflow; most returned to manual controls and restored operations quickly. The agencies characterized the observed disruption as limited, while warning that insecure OT environments can have physical consequences.
Rank #3
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
In a December 9, 2025 release, the NSA named CARR, Z-Pentest, NoName057(16), Sector16, and affiliated groups in connection with opportunistic attacks exploiting inadequately secured VNC connections to reach OT control devices. The NSA said these groups often seek notoriety and exaggerate impacts, but have also been observed causing damage. This activity is also separate from the campaign Amazon described.
What defenders should prioritize
Reduce exposure and strengthen access
- Keep HMIs and PLCs off the public internet. If remote access is necessary, put it behind a firewall or VPN and require a strong password and MFA.
- Remove factory-default and weak passwords, patch VNC and other systems, and allow access only from authorized IP addresses.
- Replace end-of-life HMIs as feasible. Unsupported devices can leave operators with fewer options for patching and maintenance.
Watch for signs of access and configuration changes
For the edge-device activity Amazon described, monitoring priorities include unexpected packet-capture files or utilities, exposed management interfaces, interactive sessions to appliance administration portals from unexpected IP addresses, and credential reuse or replay against online services. Amazon’s AWS-oriented suggestions include least-permissive security-group rules, placing management interfaces in private subnets, identity federation and IAM roles, VPC Flow Logs, CloudTrail, GuardDuty, and vulnerability scanning. These are recommended controls, not a guarantee that any single measure prevents compromise.
For OT environments, log remote access, check PLC logic for unauthorized changes, and back up HMI engineering logic, configurations, and firmware so they can be restored if altered.
Rank #4
- Wi-Fi 6 Mesh Wi-Fi - Next-gen Wi-Fi 6 AX3000 whole home mesh system to eliminate weak Wi-Fi for good(2×2/HE160 2402 Mbps plus 2×2 574 Mbps)
- Whole Home WiFi Coverage - Covers up to 6500 square feet with seamless high-performance Wi-Fi 6 and eliminate dead zones and buffering. Better than traditional WiFi booster and Range Extenders
- Connect More Devices - Deco X55(3-pack) is strong enough to connect up to 150 devices with strong and reliable Wi-Fi
- Our Cybersecurity Commitment - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement
- More Gigabit Ports - Each Deco X55 has 3 Gigabit Ethernet ports(6 in total for a 2-pack) and supports Wired Ethernet Backhaul for better speeds. Any of them can work as a Wi-Fi Router
Prepare to operate safely and recover
Maintain the ability to run processes manually, and use operational interlocks, cyber-physical safety systems, and cyber-informed engineering to limit the consequences of unauthorized changes. These safeguards matter because an intrusion into an exposed control system can affect a physical process, not just data or accounts.
CISA’s 2024 fact sheet also lists its Cyber Hygiene services and assessments for eligible organizations. The cited public guidance does not endorse commercial products.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallIf an FSB-related intrusion is suspected
The FBI advises suspected victims of the FSB activity to evaluate routers and other networking devices for configuration changes or malware before filing a report, then include those findings in the report to the FBI. This advice applies to the FBI’s separate FSB warning, not as a specific response procedure for every incident described above.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

