China-Linked Fire Ant Turned Cisco Routers, TACACS Servers Into Espionage Platforms
The China-nexus espionage gr 2026-9-1 14:11:27 Author: thecyberexpress.com(查看原文) 阅读量:7 收藏

Cross-section illustration of a network router with a covert red tunnel passing through it and log entries fading to blank, representing Fire Ant espionage on Cisco IOS XR routers and TACACS servers.

The China-nexus espionage group Fire Ant has moved from compromising virtualization platforms to implanting Cisco IOS XR routers and TACACS authentication servers. They are using them to capture traffic, harvest administrator credentials and suppress the logs defenders rely on, said researchers at Sygnia, an incident response firm.

Researchers first documented Fire Ant in July 2025 for deep intrusions into VMware ESXi and vCenter environments. The new report describes the same actor operating a layer lower, in what researchers call the trust layer — the routers, authentication servers and Linux management hosts that carry traffic, authorize administrators and record what happened.

Researchers assess a strong overlap with UNC3886, the China-linked group Google’s Mandiant tracks for targeting network edge and virtualization systems, while noting the tooling has evolved rather than been reused wholesale. The activity is distinct from the Salt Typhoon and Volt Typhoon campaigns.

Also read: ‘UNC3886 is Attacking Our Critical Infrastructure Right Now’: Singapore’s National Security Lawmaker

On Cisco IOS XR routers, the operators deployed custom control-plane malware and created generic routing encapsulation tunnel interfaces that left no trace in device configuration files.

On authentication infrastructure, a previously unreported toolkit that the researchers named TacTap injected a malicious library into the tac_plus daemon to capture credentials as administrators authenticated, storing them with simple XOR obfuscation.

A second new implant, BridgeAgent, ran on Linux jump hosts disguised as a Zabbix monitoring agent and persisted through a systemd unit.

Anti-forensic work was central to the operation. Researchers said the actor modified syslog functions to filter and delete selected records, rewrote wtmp and utmp login records, suppressed authentication logging, filtered command output, disabled SELinux and altered firewall rules. Backdoors were triggered by magic strings inside network packets rather than by listening ports, leaving little for port-based detection to find, and some components had lain dormant since 2025.

Asaf Perlman, Sygnia’s director of incident response, said the group’s aim went beyond individual machines. “Fire Ant didn’t just compromise systems. It compromised the trust layer those systems depend on.”

Also read: Russia’s FSB-Linked Hackers Targeting Cisco Network Gear Used in Critical Infrastructure

The firm withheld the victim’s identity and sector to protect the organization and connected networks, and said the pattern is most consistent with long-term espionage. Critical infrastructure networks were reached but appear to have been limited to reconnaissance. Cisco did not immediately comment.

The findings feed directly into an active regulatory push. CISA and allied agencies have issued repeated hardening guidance for network edge devices after the Salt Typhoon telecom intrusions, and operators covered by the EU’s NIS2 directive face supply-chain and incident-reporting duties that extend to routers and authentication systems. Detecting this class of intrusion requires out-of-band verification that many organizations do not yet perform.

Sygnia published file hashes and YARA rules for the malware and persistence components.


文章来源: https://thecyberexpress.com/cisco-routers-tacacs-servers-espionage/
如有侵权请联系:admin#unsafe.sh