Fire Ant weaponizes Cisco routers as covert surveillance hubs

1 min read
Source: BleepingComputer
Fire Ant weaponizes Cisco routers as covert surveillance hubs
Photo: BleepingComputer
TL;DR Summary

Sygnia researchers say Fire Ant has shifted from targeting VMware to compromising Cisco IOS XR routers, TACACS servers, and Linux management hosts, deploying a persistent malware that creates a fake systemd service, suppresses logs, and uses a GRE tunnel to route traffic to a Linux staging server for reconnaissance. The attackers capture router traffic as PCAPs, upload them to external FTP servers, and probe connected high-value networks; they also uncovered BridgeAgent, a backdoor masquerading as a Zabbix agent that supports TLS reverse shells and additional payload execution. The operation overlaps with UNC3886 but features distinct artifacts, and investigators warn to validate logs and IoCs to detect the actors’ activity.

Share this article

Reading Insights

Total Reads

1

Unique Readers

8

Time Saved

3 min

vs 4 min read

Condensed

85%

747109 words

Want the full story? Read the original article

Read on BleepingComputer