Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Fire Ant Malware Targets Cisco Routers and Network Infrastructure

Fire Ant, a China-nexus cyberespionage group, is targeting more than virtualization platforms. Cybersecurity researchers at Sygnia recently observed the group targeting Cisco IOS XR Routers, authentication systems, and Linux management hosts.

After compromising a router, Fire Ant can use it as an operational platform rather than only as a stepping stone. Sygnia said the group collected traffic, established connections, manipulated command output, and suppressed logging to reduce the chance of detection.

The group also targeted TACACS servers, which administrators use to authenticate access to network hardware. Sygnia said Fire Ant harvested credentials from these systems and weakened the reliability of audit logs.

On Linux management hosts, researchers found multiple persistent implants and backdoors, including a custom SSH backdoor and malware that spoofed legitimate software. The campaign appears designed to establish access to other environments through the victim organization’s infrastructure and trust relationships. Sygnia described this as a “target behind the target” scenario.

Little is known about Fire Ant beyond its first observation in 2025. Some researchers have reported significant overlaps with UNC3886, a Chinese espionage group previously observed by Google, but important differences make the attribution inconclusive.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.