Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 6 sources · 4 days · First seen · Last updated
Fire Ant cyberespionage campaign against Cisco routers
Overview
A China-linked threat actor known as ‘Fire Ant’ has been identified conducting a sophisticated cyberespionage campaign targeting Cisco routers running the IOS XR operating system.
Reports from cybersecurity firm Sygnia indicate that the group compromises Cisco devices, TACACS authentication servers, and Linux management hosts to establish long-term persistence. To evade detection, the actors utilize advanced techniques such as suppressing syslog and command-line interface outputs, and operating generic routing encapsulation (GRE) tunnels that do not appear in running configurations or commit histories.
The group’s activities include capturing network traffic into PCAP files, stealing administrative credentials through library injection, and deploying backdoors like the Medusa rootkit and BridgeAgent. By hijacking these management paths, Fire Ant is able to map network topologies and explore connected target networks from within compromised organizational interconnections.
Entities
Timeline
-
8 days ago
[TECHNOLOGY] 2 sourcesFire Ant cyberespionage group targets Cisco routersA China-linked cyberespionage group called ‘Fire Ant’ has compromised Cisco routers to monitor traffic, steal credentials, and hide its presence from network administrators.
-
12 days ago
[TECHNOLOGY] 4 sourcesFire Ant threat actor targets Cisco routers for espionageThe China-nexus threat actor Fire Ant is targeting Cisco IOS XR routers and management infrastructure to conduct long-term espionage and steal credentials within high-value networks.
Sources
cybernoz.com · cybersecuritydive.com · dev.to · latestly.com · news.mynavi.jp · therecord.media