Fire Ant Hacks Cisco Routers for Covert Network Access
Chinese threat actor Fire Ant has been using Cisco routers as spying platforms to gain access to sensitive networks. According to Sygnia, an incident response company, Fire Ant has switched from targeting VMware hypervisors to compromising Cisco routers, TACACS authentication servers, and Linux management hosts.
The researchers discovered Fire Ant's new tactic after finding an active GRE tunnel interface on a Cisco IOS XR router that could not be explained by the running configuration or commit history. Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that ran the implant only during alternating hours.
The malware selectively suppressed syslog messages to hide tunnel-related information from legitimate administrators and established outbound Telnet connections to Fire Ant infrastructure. It also supported interactive shell access with no logging. The attackers used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers, exposing internal topology and other sensitive information.
Sygnia believes that Fire Ant's operation aimed to compromise trusted infrastructure at an initial victim and use it as a covert bridge to explore access paths into connected high-value networks. The researchers also discovered a previously undocumented backdoor called 'BridgeAgent,' which Fire Ant disguised as a legitimate Zabbix monitoring agent.