Fire Ant Moves Into the Network’s Best Seat
Fire ant, a China-linked cyber espionage operation, not the insects have been targeting some of the most trusted equipment inside corporate networks, including Cisco routers and authentication servers.
And controlling the router is rather more useful to an attacker than compromising another laptop.
Investigators from Sygnia discovered Fire Ant targeting Cisco IOS XR routers, TACACS servers and Linux management hosts after previously compromising VMware environments.
By controlling these systems, the attackers could observe network traffic, capture credentials and explore routes into other sensitive systems.
The activity showed strong similarities to the China-linked espionage group known as UNC3886, although researchers stopped short of making a definitive attribution.
Stealing Data, Then Hiding the CCTV
One compromised Cisco router contained an unexplained GRE tunnel with no normal configuration history showing how it got there.
Further investigation revealed malware specifically designed for Cisco IOS XR.
One component manipulated logging so selected messages disappeared. Another modified commands used by administrators so the attacker’s own tunnel configuration could be hidden from view.
Fire Ant also captured network traffic and uploaded packet captures to external servers.
Meanwhile, compromised TACACS authentication servers were used to harvest usernames and passwords using a tool researchers call TacTap.
Linux systems were not spared either. A backdoor named BridgeAgent disguised itself as a legitimate Zabbix monitoring component, while rootkits, SSH backdoors and other tools helped maintain long-term access.
Attackers also deleted or altered logs and attempted to disguise malicious software as legitimate security products.
The Security Lesson
The incident highlights an important point: routers, authentication servers and management hosts are not simply network plumbing.
If attackers control them, they can potentially control both the traffic and the evidence showing what happened.
Security teams should therefore include network infrastructure in forensic investigations and compare evidence across logs, memory, network traffic, authentication records and configurations.
Because when the attacker owns both the CCTV and the logbook, investigations become considerably more interesting.