Fire Ant Hackers Turn Cisco Routers into Spying Platforms
Chinese hackers known as Fire Ant have been found to be compromising Cisco routers and using them as spying platforms, according to a report by incident response company Sygnia. The researchers discovered that Fire Ant had switched from targeting VMware hypervisors to compromising Cisco routers, TACACS authentication servers, and Linux management hosts.
Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that ran the implant only during alternating hours. The malware selectively suppressed syslog messages to hide tunnel-related information from legitimate administrators, established outbound Telnet connections to Fire Ant infrastructure, and supported interactive shell access with no logging.
The attackers also used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers. These captures could expose internal topology, administrative connections, authentication flows, routing relationships, and traffic exchanged with connected networks.