China-Linked Hackers Abuse Cisco Routers for Covert Network Access
A sophisticated hacking group linked to China has compromised Cisco routers to gain covert access to entire networks, according to security firm Sygnia. The threat actor, known as Fire Ant, used privileged access to monitor network traffic and establish connections into surrounding environments.
The attackers compromised Linux management hosts and the Terminal Access Controller Access-Control System (TACACS), enabling unauthorized access to authentication systems. They also scanned and made connection attempts toward high-value environments, including critical infrastructure systems.
Sygnia discovered that Fire Ant had gained privileged access to Cisco IOS XR routers by hiding evidence of their activity in commit logs. The hackers used Generic Routing Encapsulation (GRE) tunnels to create a foothold in the network, allowing them to monitor traffic and capture credentials for further intrusion.