Researchers at Sygnia discovered the new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by the running configuration or commit history. Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that runs the implant only during alternating hours.
The malware suppresses syslog messages to hide tunnel-related information from administrators, establishes outbound Telnet connections to Fire Ant infrastructure, and supports interactive shell access with no logging. The attackers also used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers.
Sygnia explains that this behavior shifts the router's role from a transit device to a collection platform, giving the actor a vantage point for observing traffic moving through trusted network paths. The concealed GRE tunnel connected one compromised router to a legacy Linux server, which Fire Ant used as a staging and reconnaissance system. From there, the attackers probed systems in connected high-value environments, including critical infrastructure, over ports commonly used for SSH, web services, SMB/RPC, and RDP.
Sygnia believes the operation aimed to compromise trusted infrastructure at an initial victim and use it as a covert bridge to explore access paths into connected high-value networks, a tactic they dub 'target behind the target.' The researchers also discovered a previously undocumented backdoor called 'BridgeAgent,' which Fire Ant disguised as a legitimate Zabbix monitoring agent. The backdoor persists as a root-level systemd service and supports TLS reverse shells and execution of additional payloads.