started · updated
Fire Ant cyberespionage group targets Cisco routers
A cybersecurity firm, Sygnia, has identified a China-linked threat group known as ‘Fire Ant’ that has been compromising Cisco routers to build an advanced attack platform. The group specifically targets Cisco IOS XR routers, installing malware designed to monitor network traffic and search for access to other critical networks.
According to the investigation, the group uses sophisticated techniques to remain undetected, including suppressing router logs and altering information shown to network administrators. The attackers have been observed using legitimate administrator accounts to blend in with normal operations and have established hidden network tunnels to facilitate their activities.
Beyond routers, the group’s activities have extended to targeting TACACS servers and Linux management hosts. They have been found using custom SSH backdoors, rootkits, and credential-harvesting tools to maintain persistence and escalate access within compromised environments. While the specific Chinese government agency linked to the group has not been identified, the investigation highlights a rapid evolution in the group’s ability to hijack trusted infrastructure.