China-Linked Hackers Use Compromised Routers to Steal Admin Credentials
A China-linked cyberespionage group, tracked by cybersecurity firm Sygnia as Fire Ant, compromised Cisco routers and hid its activity from network administrators. The group recorded traffic moving through the devices and used them to probe other high-value networks.
The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment, allowing them to capture administrator credentials. Sygnia named the tool used for this purpose TacTap and said it was unaware of this technique having been publicly documented before.
Cisco issued a critical security-hardening update for IOS XR, the router operating system involved in Sygnia's investigation, addressing seven groups of vulnerabilities discovered through internal testing and not known to be actively exploited. However, Sygnia did not identify a Cisco vulnerability used in the attacks.