Fire Ant weaponizes Cisco routers as covert surveillance hubs

Sygnia researchers say Fire Ant has shifted from targeting VMware to compromising Cisco IOS XR routers, TACACS servers, and Linux management hosts, deploying a persistent malware that creates a fake systemd service, suppresses logs, and uses a GRE tunnel to route traffic to a Linux staging server for reconnaissance. The attackers capture router traffic as PCAPs, upload them to external FTP servers, and probe connected high-value networks; they also uncovered BridgeAgent, a backdoor masquerading as a Zabbix agent that supports TLS reverse shells and additional payload execution. The operation overlaps with UNC3886 but features distinct artifacts, and investigators warn to validate logs and IoCs to detect the actors’ activity.
- Chinese Fire Ant hackers turn Cisco routers into spying platforms BleepingComputer
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs The Hacker News
- China-linked Fire Ant Hides Inside Trusted Infrastructure Security Affairs
- State-linked actor targets Cisco routers for espionage Cybersecurity Dive
- Sygnia Highlights China-Nexus Fire Ant Threat Targeting Trusted Infrastructure World Business Outlook
Reading Insights
1
8
3 min
vs 4 min read
85%
747 → 109 words
Want the full story? Read the original article
Read on BleepingComputer