Fire Ant Hacking Group Compromises Cisco Routers as Covert Surveillance Points
A China-linked hacking group called Fire Ant has compromised Cisco routers and turned them into covert surveillance points inside targeted networks, according to research by incident response company Sygnia.
The attackers relied on custom malware, hidden GRE tunnels, and anti-forensic techniques to maintain access, monitor traffic, and move towards other connected systems.
The compromised routers gave the attackers a trusted position inside the network, allowing them to observe traffic moving through connected systems. Researchers found an active Generic Routing Encapsulation, or GRE, tunnel interface on a Cisco IOS XR router that could not be explained by its normal configuration or commit history.