Fire Ant Expands Reach with Novel Attacks on Trusted Infrastructure
Sygnia's recent investigation has uncovered new activity by Fire Ant, a China-nexus threat actor targeting trusted infrastructure. The threat actor has been leveraging novel attack tools and methods to target Cisco IOS XR routers, turning them into operational platforms that suppress evidence of threat actor activity, collect traffic and credentials, and enable Fire Ant to explore other access points.
The compromised routers are used as a vantage point for reach, visibility, and control, allowing the threat actor to compromise both direct and connected high-value environments. Sygnia's investigation has also uncovered two novel tools: BridgeAgent, a masquerading implant configured for tunnelling and persistence through a zabbix_agent.service systemd unit, and TacTap, a TACACS credential-collection toolset.
The threat actor is using these tools to collect credentials and weaken confidence in administrative audit trails. Fire Ant's interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim.