Fire Ant Compromises Critical Infrastructure with Router and Server Hacks
The Fire Ant threat actor has expanded its espionage operations to compromise critical infrastructure, targeting Cisco routers and TACACS servers. This marks a deliberate shift from conventional endpoints to infrastructure-control-plane assets.
Fire Ant compromised Cisco IOS XR routers, modifying their operational environment to support persistence, covert communications, traffic collection, and anti-forensics. An unexplained GRE tunnel interface was active on the affected router despite having no matching running configuration or commit-history record.
The router toolkit included a persistence script masquerading as a legitimate boot-related service and an implant named acpid, which was launched intermittently to reduce continuous process visibility. Fire Ant also manipulated command output by modifying the IOS XR command-execution path to append exclusion filters to show commands, hiding tunnel-related details.
The compromised routers were used for packet capture, with Fire Ant executing router-administration workflows using a legitimate account to collect PCAP files from multiple interfaces and upload them to external FTP infrastructure. This exposure of network topology, management communications, authentication flows, routing relationships, and traffic patterns across connected environments poses significant risks.