Chinese Hackers Use Compromised Cisco Routers for Further Attacks
Chinese hackers have been using compromised Cisco routers as a platform for further attacks on organizations. The hacking operation, dubbed 'Fire Ant' by cybersecurity firm Sygnia, involved an array of methods to compromise popular Cisco routers and use them as a jumping off point to monitor organizations, steal credentials, and break into other organizations.
According to Sygnia's report, the hackers compromised trust layers in systems, including routers, authentication servers, and management infrastructure. This allowed them to collect intelligence and credentials before building durable access and concealing their activity.
The researchers found that the attackers used new tools for persistence and to collect critical credentials, enabling wider access to an organization. They also hid logs and took measures to manipulate potential evidence of their activity, often deleting files and tampering with firewall rules.