
Fire Ant weaponizes Cisco routers as covert surveillance hubs
Sygnia researchers say Fire Ant has shifted from targeting VMware to compromising Cisco IOS XR routers, TACACS servers, and Linux management hosts, deploying a persistent malware that creates a fake systemd service, suppresses logs, and uses a GRE tunnel to route traffic to a Linux staging server for reconnaissance. The attackers capture router traffic as PCAPs, upload them to external FTP servers, and probe connected high-value networks; they also uncovered BridgeAgent, a backdoor masquerading as a Zabbix agent that supports TLS reverse shells and additional payload execution. The operation overlaps with UNC3886 but features distinct artifacts, and investigators warn to validate logs and IoCs to detect the actors’ activity.













