Fire Ant Expands Campaign, Compromises Critical Infrastructure Networks
A China-linked cyber espionage group known as Fire Ant has expanded its long-running campaign to compromise high-value networks, including those used for critical infrastructure. The group, also tracked as UNC3886, has been exploiting Cisco IOS XR routers and Terminal Access Controller Access-Control System (TACACS) servers to steal credentials and suppress security logs.
Sygnia, the incident response firm that investigated the intrusion, said the actor turned the compromised routers into collection platforms, capturing network traffic, harvesting credentials, and suppressing logging and telemetry. The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments but limited activity against those networks to scanning and connection attempts.
The investigation began with an anomaly on a Cisco IOS XR router, where a Generic Routing Encapsulation (GRE) tunnel interface was operating with no running configuration or commit history. Tracing the tunnel led investigators to a legacy Linux system, from which Fire Ant ran repeated connection attempts against administrative and service ports on connected networks.
The actor also used the routers to capture packet captures (PCAPs) from multiple Cisco devices, uploading them to external FTP servers. On the TACACS server, Sygnia identified a credential-collection toolset it tracks as TacTap. The captured credentials were written to /var/log/.tacplus.acct and lightly obfuscated with a single-byte XOR key of 0xEF.