The United States Department of State is offering a reward of up to $10 million for information about three officers of Russia 's Federal Security Service (FSB) involved in cyberattacks against critical US infrastructure (on behalf of the Russian government).

These three officers, Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov and Pavel Aleksandrovich Akulov, belong to FSB Center 16 or Military Unit 71330, which is known by various names such as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly and Koala Team.
See also: Iran's Homeland Justice Targets Over 100 Embassy Emails
FSB: Charges against officers – hackers
In March 2022, the three FSB officers were charged with participating in a campaign that took place between 2012 and 2017. They targeted U.S. government agencies, including the Nuclear Regulatory Commission. They also targeted energy companies, such as Wolf Creek Nuclear Operating Corporation, which operates a nuclear power plant in Burlington, Kansas.
The State Department said in a tweet: “We want information about three FSB officers who conducted malicious cyber activities against critical US infrastructure on behalf of the Russian government. These officers also targeted more than 500 foreign energy companies in 135 other countries.”
The Ministry encouraged anyone with information about their activities to contact the Rewards for Justice via the Tor-based tip reporting channel.

Exploitation of vulnerabilities
The FBI warned in August that FSB officers were exploiting the CVE-2018-0171 vulnerability in Cisco networking equipment that had reached the end of its life. The exploitation of this vulnerability occurred primarily last year, with the aim of breaching companies with critical infrastructure in the US . Hackers were able to remotely execute arbitrary code on unpatched devices.
See also: TinyLoader: New malware loader attacks Windows users
Cisco, which first detected the attacks four years ago, updated its advisory and urged network administrators and security teams to update their devices as soon as possible.
Cisco Talos reported that the Russian state-sponsored hacking group is aggressively exploiting this vulnerability to compromise unpatched devices belonging to telecommunications organizations, higher education institutions, and manufacturing companies across North America, Europe, Asia, and Africa.
The same Russian group is known for its attacks against government organizations at the state and local levels as well as entities in the aviation sector.
Government hackers
The case of the three FSB officers wanted by the US highlights a broader reality: cybersecurity has become one of the main axes of geopolitical confrontation. We are no longer talking about isolated attacks by independent hackers, but about systematic operations funded and directed by state mechanisms. This creates a landscape where the lines between war, espionage and cybercrime are becoming increasingly blurred.

The choice of energy infrastructure as targets is characteristic: their disruption can cause ripple effects on the economy, national security and the daily lives of citizens. Attacks on such systems function not only as espionage operations but also as tools of intimidation.
See also: Hackers leverage Hexstrike-AI for Zero Day exploit
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, the case highlights the perennial problem of critical organizations relying on old or outdated systems. The exploitation of a vulnerability that was reported as early as 2018 demonstrates that technical weaknesses can easily become geopolitical weapons when neglected.
The US move to offer large sums of money for information has a dual purpose: on the one hand, to gather evidence that will allow the prosecution of those responsible, and on the other, to send a message of deterrence to other state hacker groups.
In June, the US State Department announced a reward of up to $10 million for information on government hackers linked to the operation of the RedLine infostealer and its suspected creator, Russian Maxim Alexandrovich Rudometov.
The question that remains is whether such measures are enough in a world where cyberspace has evolved into the new frontline of conflict.
Source: bleepingcomputer
