A sophisticated cyber campaign by China-based hackers, known as 'Fire Ant,' has been uncovered by cybersecurity firm Sygnia. This operation involved compromising popular Cisco routers, which were used as a platform to launch further attacks on various organizations. The campaign's complexity and effectiveness were notable, as it did not merely compromise systems but also the underlying trust infrastructure, such as routers and management systems, which organizations often consider outdated. This breach allowed the attackers to gain significant reach, visibility, and control over targeted environments.
Sygnia's report details how the Fire Ant group exploited these routers to collect intelligence and credentials, creating persistent access while concealing their activities. They targeted infrastructure components like routers, hypervisors, and access appliances to gather valuable insights and plan further attacks. The campaign focused on Cisco IOS XR routers, using new tools to secure persistent access and collect critical credentials, enabling the attackers to widen their reach within organizations.
The hackers manipulated logs and firewall rules to hide their presence, making it difficult for defenders to detect their activities. The malware employed was specifically designed to control and modify routers to suit the attackers' needs. By capturing traffic from multiple routers, the attackers gained a comprehensive view of the network environment, which facilitated lateral movement and cross-network access planning.
Fire Ant's activities highlight the need for organizations to treat routers and similar infrastructure as critical security assets. The report emphasizes the importance of monitoring, hardening, and preparing incident response for these components. Chinese state-backed groups have historically targeted Cisco devices, with previous campaigns like Volt Typhoon and Salt Typhoon focusing on similar vulnerabilities. The findings from Sygnia demonstrate the necessity for continuous validation of trust relationships across network management infrastructure to prevent such breaches.


