China-Linked Group Hacks Cisco Routers for Covert Espionage
A sophisticated China-linked cyberespionage group has been compromising Cisco IOS XR routers and other critical infrastructure to intercept credentials, collect network traffic, and conceal evidence of its presence. The group, tracked by incident-response company Sygnia as Fire Ant, has expanded its operations beyond virtualisation infrastructure.
Fire Ant targeted the trusted infrastructure that routes traffic, authenticates administrators, and records security activity. By controlling those systems, the attackers obtained a privileged view of the victim's network and an opportunity to manipulate the evidence defenders would normally use to investigate the breach.
The compromised routers were transformed into operational platforms capable of creating covert network paths, capturing traffic, and suppressing logging. The attackers also breached a Terminal Access Controller Access-Control System Plus (TACACS+) server, allowing them to intercept authentication sessions and collect administrative credentials passing through a central access-control point.