AUTO-UPDATED

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

The China-nexus cyber espionage group Fire Ant has expanded its operations to compromise Cisco routers, TACACS servers, and Linux hosts to intercept network traffic and harvest administrative credentials.

Key Points

  • Fire Ant uses custom malware to turn Cisco IOS XR routers into collection platforms that capture network traffic while suppressing logs and telemetry.
  • The group deployed a new tool called TacTap to inject malicious libraries into TACACS authentication processes, allowing for the theft of sensitive network credentials.
  • Attackers established persistent access on Linux management hosts using rootkits and backdoors disguised as legitimate security agents like SentinelOne and Cybereason.
  • The campaign, which overlaps with tactics attributed to the UNC3886 threat cluster, involves sophisticated efforts to hide tunnel configurations and manipulate system command outputs.
  • Investigators discovered that the group actively probes high-value environments and critical infrastructure, though confirmed compromises in those specific sectors remain limited.

Why it Matters

This campaign demonstrates a significant evolution in espionage tradecraft by targeting the foundational infrastructure that manages and authenticates enterprise network traffic. By compromising routers and TACACS servers, attackers gain deep visibility into trusted network paths, making it increasingly difficult for organizations to detect unauthorized access or data exfiltration.
Internet Published by info@thehackernews.com (The Hacker News)
Read original