Fire Ant Compromises Critical Infrastructure with Sophisticated Hacking Campaign
Cybersecurity firm Sygnia has uncovered a sophisticated hacking campaign by threat actor Fire Ant, which has compromised Cisco routers and TACACS servers to target critical infrastructure.
Fire Ant's latest operations show a deliberate shift towards controlling the infrastructure layer, rather than conventional endpoints. By taking over routers, authentication servers, and management systems, the group gained visibility into network paths, administrator sessions, credentials, and cross-environment trust relationships.
The compromised routers were used for packet capture, with Fire Ant collecting PCAP files from multiple interfaces and uploading them to external FTP infrastructure. The attackers also manipulated command output, hiding tunnel-related details from administrators using the router CLI.
Sygnia researchers found that Fire Ant used a credential-theft toolset called TacTap on compromised TACACS servers, allowing the group to intercept administrative connections and steal credentials. This campaign demonstrates how attackers can weaponize trusted infrastructure assets to reach connected high-value environments.