Fire Ant Threat Actor Targets Trusted Infrastructure with Novel Attacks
Sygnia, a global cyber readiness and response team, has revealed new activity by a China-nexus threat actor known as 'Fire Ant'. This adversary is targeting trusted infrastructure that routes, authenticates, connects, and manages high-value environments. Fire Ant has leveraged novel attack tools and methods to target Cisco IOS XR routers.
The investigation found that these routers were turned into operational platforms used to suppress evidence of threat actor activity, collect traffic and credentials, and enable further access points for spreading to other organizations.
This new wave of attacks highlights the evolving nature of cyber threats and the importance of staying vigilant in protecting critical infrastructure. Sygnia's findings underscore the need for increased security measures and cooperation between organizations to combat these emerging threats.