Fire Ant Malware Expands Reach to Cisco Routers and Linux Hosts
Cybersecurity researchers at Sygnia have discovered that Fire Ant, a China-linked cyberespionage group, has expanded its targets to include not just virtualization platforms but also Cisco routers and Linux management hosts.
The group's malware, dubbed Fire Ant, compromises routers by turning them into operational platforms, allowing attackers to collect traffic, establish connections, manipulate command output, and suppress logging. This tactic is particularly insidious as it allows the attackers to blend in with legitimate network activity, making detection more challenging.
Fire Ant also targets authentication systems, specifically TACACS servers, which are used by administrators to authenticate when accessing network hardware. By compromising these systems, attackers can harvest valuable credentials and weaken the reliability of audit logs.
The campaign's goal appears to be to establish a foothold that allows attackers to reach other environments. Sygnia describes this as a 'target behind the target' scenario, where Fire Ant is not only attempting to compromise a single environment but also aiming to control infrastructure that enables visibility, collection, and potential access beyond the immediate victim.