China-Linked Fire Ant Exploits Cisco Routers for Credential Theft and Log Suppression
A China-linked group, Fire Ant, has compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts to steal credentials and suppress security logs. The attackers used custom malware, including a modified system library to filter logs and a backdoor masquerading as a monitoring agent, while undermining forensic evidence.
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.
Sygnia, the incident response firm that investigated the intrusion, said the actor
*** END OF TRANSMISSION ***