Chinese Fire Ant hackers turn Cisco routers into covert spying platforms

Threat group deploys custom malware on IOS XR routers, establishing hidden GRE tunnels and capturing network traffic

edit
By LineZotpaper
Published
Read Time2 min
Chinese state-sponsored threat actor Fire Ant has evolved its tactics from targeting VMware hypervisors to compromising Cisco IOS XR routers, deploying custom malware that establishes hidden GRE tunnels, suppresses syslog messages, and captures network traffic for espionage, according to incident response firm Sygnia.

Researchers at Sygnia discovered the new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by the running configuration or commit history. Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that runs the implant only during alternating hours.

The malware suppresses syslog messages to hide tunnel-related information from administrators, establishes outbound Telnet connections to Fire Ant infrastructure, and supports interactive shell access with no logging. The attackers also used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers.

Sygnia explains that this behavior shifts the router's role from a transit device to a collection platform, giving the actor a vantage point for observing traffic moving through trusted network paths. The concealed GRE tunnel connected one compromised router to a legacy Linux server, which Fire Ant used as a staging and reconnaissance system. From there, the attackers probed systems in connected high-value environments, including critical infrastructure, over ports commonly used for SSH, web services, SMB/RPC, and RDP.

Sygnia believes the operation aimed to compromise trusted infrastructure at an initial victim and use it as a covert bridge to explore access paths into connected high-value networks, a tactic they dub 'target behind the target.' The researchers also discovered a previously undocumented backdoor called 'BridgeAgent,' which Fire Ant disguised as a legitimate Zabbix monitoring agent. The backdoor persists as a root-level systemd service and supports TLS reverse shells and execution of additional payloads.

§

Analysis

Why This Matters

  • The attack demonstrates a dangerous escalation in adversary tradecraft, using network infrastructure as a passive collection platform rather than just a transit point.
  • Compromised routers can expose internal topology, administrative connections, authentication flows, and traffic exchanged with connected networks, potentially enabling access to critical infrastructure.
  • The tactic of targeting 'trusted infrastructure' to reach a 'target behind the target' makes detection harder and could inspire copycat operations.

Background

Fire Ant is a Chinese state-sponsored threat group known for targeting telecommunications, technology, and government entities. The group has previously focused on compromising VMware hypervisors and other virtualization platforms. This latest campaign marks a shift toward network infrastructure, specifically Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The use of custom malware and hidden GRE tunnels represents a sophisticated evasion technique.

Key Perspectives

Sygnia (Incident Response Firm): The researchers view this as a strategic evolution, with the router becoming a 'collection platform' that allows the adversary to observe trusted traffic unobtrusively. They emphasize the difficulty of detecting such implants when syslog suppression and out-of-band command channels are used. Network Defenders: Organizations relying on Cisco IOS XR routers must scrutinize for unexplained GRE tunnels, periodic system services, and suppressed syslog messages. The attack highlights the need to treat network devices as security endpoints, not just pass-through equipment. Targeted Sectors: Critical infrastructure operators and high-value enterprises face elevated risk, as Fire Ant specifically probes for access paths into connected sensitive networks.

What to Watch

  • Reports of unexplained GRE tunnels or outbound Telnet connections from Cisco routers
  • Detection of BridgeAgent backdoor disguised as Zabbix agent
  • Further disclosures from Sygnia or other researchers about Fire Ant's evolving toolset
  • Potential advisories from Cisco regarding mitigation or detection signatures

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.