Fire Ant Exploits Cisco Routers for Network Espionage
A China-linked threat actor known as Fire Ant has compromised Cisco IOS XR routers to spy on networks, steal credentials, and maintain hidden access. The campaign highlights how attackers can use routers not only for traffic management but also as surveillance and attack platforms.
Investigations revealed an unexplained GRE tunnel interface on a Cisco IOS XR router, which was active without any matching configuration or commit history. This suggested that the router's operational state had been altered while normal administrative records were manipulated or hidden.
The malware modified the router's logging process to selectively prevent messages from being forwarded, suppressing important security events. It also added filters to router output to hide tunnel settings, routing details, and configuration information from administrators.