Particle.news

Fire Ant Turns Cisco Routers Into Spy Platforms

Sygnia warns control of routing and authentication infrastructure lets the actor capture traffic, harvest credentials, hide forensic evidence, threatening connected critical networks.

Overview

  • Sygnia published a detailed report on Monday linking Fire Ant’s July 2025 VMware attacks to new 2026 compromises of Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts.
  • Investigators traced the operation to an unexplained GRE tunnel on a Cisco IOS XR router that led to a legacy Linux host used as a staging point for scanning and reconnaissance of connected networks.
  • Purpose-built IOS XR implants altered syslog delivery and command output so routine checks missed the tunnel and activity while the routers recorded PCAPs and uploaded them to external FTP servers.
  • On TACACS servers the actor used an injector called acppid and a toolkit tracked as TacTap to intercept live authentication sessions and write captured credentials to an obfuscated file.
  • Sygnia released IoCs and YARA rules and advised treating routers, TACACS servers, and jump hosts as primary forensic assets while validating logs against memory, disk, network, and configuration evidence to hunt for related implants.