Chinese Fire Ant Hackers Hijack Cisco Routers for Covert Network Spying

Sygnia researchers discover that the Chinese threat actor known as Fire Ant has shifted its focus from VMware hypervisors to Cisco routers, TACACS authentication servers, and Linux management hosts. The investigation begins after analysts find an active GRE tunnel interface on a Cisco IOS XR router that the running configuration and commit history cannot explain. Fire Ant deploys custom malware on the devices that maintains persistence through a fake system service which runs the implant only during alternating hours.

The malware selectively suppresses syslog messages to hide tunnel-related information from administrators, establishes outbound Telnet connections to attacker infrastructure, and supports interactive shell access with no logging. The attackers also use their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers. These captures can expose internal topology, administrative connections, authentication flows, and traffic exchanged with connected networks, effectively turning the router from a transit device into a collection platform.

The concealed GRE tunnel links a compromised router to a legacy Linux server that Fire Ant uses for staging and reconnaissance, probing connected high-value environments, including systems tied to critical infrastructure, over ports commonly used for SSH, web services, SMB/RPC, and RDP. Sygnia describes the strategy as "target behind the target," where attackers compromise trusted infrastructure at an initial victim and use it as a covert bridge into connected high-value networks. The researchers also uncover a previously undocumented backdoor called BridgeAgent during the investigation.

Read More at the original source →