Particle.news

Fire Ant Turns Cisco Routers Into Covert Collection Platforms

Sygnia says the China‑nexus campaign implanted purpose‑built IOS XR and TACACS malware to convert routers into credential‑stealing collection platforms.

Overview

  • Sygnia disclosed Monday that investigators traced an unexplained GRE tunnel on a Cisco IOS XR router to a legacy Linux host and then found purpose‑built implants on routers, TACACS authentication servers, and Linux management hosts.
  • The attacker deployed IOS XR implants that filter syslog messages by the word “Health” and alter show commands to hide tunnel configuration so router state and audit logs can no longer be trusted.
  • On TACACS servers the actor used an injector named acppid to load a malicious library that hooks tac_plus, captures live authentication sessions, and writes XOR‑0xEF‑obfuscated credentials to /var/log/.tacplus.acct.
  • Fire Ant also deployed a Linux backdoor called BridgeAgent that masquerades as a Zabbix agent, persists via zabbix_agent.service, polls C2 over TLS on port 443, and helped stage scans toward connected high‑value networks.
  • Sygnia published IoCs and YARA rules and advised treating routers, TACACS servers, hypervisors, and jump hosts as primary forensic assets and validating logs against memory, disk, and network evidence because telemetry may be altered; the firm noted strong overlap with public reporting on UNC3886 and parallels to a 2025 CISA advisory on router collection tactics.