China-Linked Hackers Turn Cisco Routers into Monitoring Points
Chinese state-linked hackers have been targeting Cisco's widely used router models as part of an operation called 'Fire Ant', according to a recent report by Israeli cybersecurity firm Sygnia. The campaign has seen threat actors compromise network infrastructure, gathering intelligence and credentials before establishing persistent access.
The researchers found that the hackers behind the Fire Ant campaign had changed their modus operandi, focusing on compromising the infrastructure that sits between environments, such as routers, hypervisors, and Linux management hosts. This approach allows them to gain 'reach and perspective', enabling lateral movement, credential targeting, and access planning across the network.
The affected organisations have not been publicly identified, but Sygnia first reported on Fire Ant last year. The group has remained active this year, expanding its operations beyond compromising hypervisors. This campaign is linked to a group tracked by Google's Mandiant unit as UNC3886, which was implicated in attacks against major strategic organisations between 2022 and 2024.