Fire Ant: Cisco IOS XR, TACACS, and Linux Management Infrastructure Hijacked into Spying and Access Platforms

2026年9月1日1 次浏览来源:Dev.to阅读原文

1.

Overview Title: Chinese Fire Ant hackers turn Cisco routers into spying platforms Publisher: BleepingComputer Publication Date: 2026-08-31 Original Source: BleepingComputer Related Sources: Sygnia Related Malware, Threat Groups, CVEs, Products: Fire Ant, BridgeAgent, TacTap, Medusa rootkit, Cisco IOS XR, TACACS+, Linux, Zabbix Severity: High

2.

Executive Summary Fire Ant compromised Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts.

The actors used GRE tunnels, suppressed logs and CLI outputs, captured network traffic, stole credentials, and deployed multiple long-term backdoors to explore connected high-value networks.

3.

Attack Flow Turning Trusted Management Infrastructure into Relay Points Fire Ant gains high-privileged access to Cisco IOS XR routers and Linux management hosts.

The initial access vector is not disclosed.

The actors place persistence scripts and IOS XR-specific components on the routers, manipulating syslog and outputs.

They operate GRE tunnels with VRF and outbound Telnet connections that rarely appear in configurations or history logs.

They capture network traffic into PCAP files on the routers and send them to external FTP servers to gather internal network topology and authentication flows.

They deploy BridgeAgent, rootkits, custom SSH, and packet-triggered backdoors on the GRE-connected Linux hosts.

They inject libraries into using TacTap to harvest TACACS credentials.

They probe connected SSH, HTTP(S), SMB/RPC, and RDP services to verify reachability to high-value networks, including critical infrastructure.

4.

Threat Actor Positioning and Execution Environment External actors with high-privileged access to routers, TACACS servers, and Linux management hosts.

The initial access vector is unknown.

After the compromise, they explore connected target networks from inside organizational interconnections and management paths.

5.

Visibility for Victims and Administrators Victims The activity rarely appears directly on end-user screens; it manifests as minor network or authentication anomalies.

Administrators Clues include unexpected GRE tunnels, discrepancies between outputs and actual system states, missing syslog/AAA/SNMP logs, router-originated PCAPs and FTP traffic, TACACS credential files, and fake services.

6.

Success Conditions and Failure Conditions Success Conditions Execution of high-privileged code on routers or management hosts.

Connectivity from the management plane to external C2 servers and target networks.

Lack of independent validation for TACACS and logging infrastructure, combined with reliance on management device displays.

Failure Conditions / Risk Mitigation Isolate the management plane from business networks and external access, enforcing allowlisting for destinations.

Cross-check router run-state, configurations, commits, memory, files, and flows using independent sources of truth.

Monitor TACACS servers and Linux management hosts for file integrity, process injection, and credential files.

Rebuild systems from known-good images upon compromise, and rotate management credentials and trust relationships.

7.

Impact of Successful Attacks Traffic monitoring via routers, hidden tunnels, and exploration of connected target networks.

Theft of TACACS and SSH credentials, enabling impersonation of legitimate administrators.

Interference with investigations through the modification of logs, configuration displays, and authentication records.

Lateral movement to connected external parties and critical infrastructure.

8.

Observable Logs Email: Not applicable.

Proxy/SWG/DNS: Unknown HTTPS, FTP/SCP traffic from management hosts, outbound Telnet, and encrypted configuration retrieval.

Endpoint/EDR: , BridgeAgent, , , , , deleted running processes, and modifications to SELinux/iptables.

Identity/IdP: Missing TACACS authentication and command logs, management commands executed without login records, , and .

SaaS/Cloud: When connected to cloud management infrastructure

分享
Baike.dev

baike.dev helps you discover great languages, frameworks, databases, DevOps and cloud-native tools.

Quick links

About

Contribute

Found a great developer tool? Share it with the community.

Submit a tool
© 2026 baike.dev Developer EncyclopediaUpdated daily · Discover great developer tools