The China-nexus cyber espionage group Fire Ant has expanded its operations to compromise Cisco routers, TACACS servers, and Linux hosts to intercept network traffic and harvest administrative credentials.
Key Points
- Fire Ant uses custom malware to turn Cisco IOS XR routers into collection platforms that capture network traffic while suppressing logs and telemetry.
- The group deployed a new tool called TacTap to inject malicious libraries into TACACS authentication processes, allowing for the theft of sensitive network credentials.
- Attackers established persistent access on Linux management hosts using rootkits and backdoors disguised as legitimate security agents like SentinelOne and Cybereason.
- The campaign, which overlaps with tactics attributed to the UNC3886 threat cluster, involves sophisticated efforts to hide tunnel configurations and manipulate system command outputs.
- Investigators discovered that the group actively probes high-value environments and critical infrastructure, though confirmed compromises in those specific sectors remain limited.