started · updated
Fire Ant threat actor targets Cisco routers for espionage
A sophisticated China-nexus threat actor known as Fire Ant is conducting an espionage campaign by targeting Cisco routers running the IOS XR operating system. According to a report by Sygnia, the group has expanded its reach into trusted network environments, including high-value networks and critical infrastructure.
The attackers compromise Cisco devices, TACACS authentication servers, and Linux management hosts to establish long-term persistence. They utilize several advanced techniques to evade detection, such as operating generic routing encapsulation (GRE) tunnels that do not appear in running configurations or commit histories. The group also manipulates syslog and command-line interface outputs to hide their presence.
Fire Ant’s activities include capturing network traffic into PCAP files, stealing administrative credentials through the injection of libraries into tac_plus, and deploying various backdoors like the Medusa rootkit and BridgeAgent. By hijacking these management paths, the actors are able to map network topologies and explore connected target networks from within organizational interconnections.