Fire Ant Hackers Turn Cisco Routers into Surveillance Platforms
Fire Ant, a hacking group, has been compromising Cisco routers to spy on networks and reach critical infrastructure. The actors have turned these routers into platforms for surveillance, remote connectivity, and movement towards high-value environments.
The campaign shows how an intruder can use a router as more than just a gateway. Fire Ant created a GRE tunnel absent from running configuration and commit records, captured network traffic, and sent PCAP files to external FTP services.
Sygnia analysts identified the activity while examining an intrusion that stretched across routers, Linux management hosts, and TACACS authentication servers. The compromised environment served as a bridge into connected targets, allowing operators to probe systems associated with critical infrastructure.
The risk extends beyond the breached organization, as control of an appliance can expose data and open a route deeper into an environment. Fire Ant's router toolkit was built for the IOS XR control plane, which allowed them to capture packets from several router interfaces and upload the data to external FTP infrastructure.