China-Linked Fire Ant Group Targets Cisco Routers with Malware
A China-linked cyber group has been targeting Cisco routers, compromising their security and using them to monitor network traffic and search for access to other high-value networks. The group, called Fire Ant by cybersecurity firm Sygnia, installed malware on affected devices that could suppress router logs and change the information shown to administrators, making it difficult to detect their activity.
According to Sygnia's investigation, Fire Ant targeted Cisco routers running IOS XR and used legitimate administrator accounts to make their activity appear like normal network operations. The group also collected network traffic passing through compromised routers and sent the captured data to external servers.
Sygnia discovered malware called TacTap, which could capture administrator login credentials during the login process, allowing Fire Ant to gain unauthorized access to network equipment. The firm found evidence of scanning and connection attempts by Fire Ant to other high-value networks, including critical infrastructure, but did not confirm that these additional systems were successfully breached.
The methods used by Fire Ant are similar to those linked to UNC3886, another China-linked cyberespionage group investigated by Google-owned Mandiant. However, Sygnia has not confirmed that the two groups are the same.