China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
AI Summary
A China-nexus cyber espionage group tracked as Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, enabling credential theft, traffic interception, and suppression of security telemetry. The group deployed custom malware including TacTap, a library injector targeting the tac_plus authentication process, and BridgeAgent, a Linux backdoor disguised as a Zabbix agent. The attackers manipulated router configurations to hide malicious GRE tunnels and exfiltrated packet captures to external FTP servers, while also obfuscating stolen credentials using XOR encryption. The campaign shows strong overlap with UNC3886, though definitive attribution remains unconfirmed.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 18 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | /usr/sbin/acppid | Details → |
| SHA-1 | 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00 | Details → |
| Filename | /lib/libseconfd.so | Details → |
| SHA-1 | 955cd45a2f6f226a2fdf44b329af1c8dde90cb38 | Details → |
| Filename | /var/log/.tacplus.acct | Details → |
| Filename | /usr/bin/acpid | Details → |
| SHA-1 | be6b27f429324a4af05a310d8ec9635e37c68a94 | Details → |
| Filename | /pkg/bin/dhcpd_show_issu_status | Details → |
| SHA-1 | 1682b652a15bde732489f22809b0b7594c228fd3 | Details → |
| Filename | /pkg/bin/hd | Details → |
| SHA-1 | b149fa3a34bd585e7a674a4fd9538437bd06f514 | Details → |
| Filename | /etc/rc.d/init.d/grub-rommon | Details → |
| Filename | /var/tmp/audit | Details → |
| SHA-1 | 13f0c2a598e3aa63856c032a96b110aed963f0e8 | Details → |
| Filename | /var/tmp/ping | Details → |
| SHA-1 | 5ba1242050b5b447052b210788a5a25593d6987d | Details → |
| Filename | /opt/.ICEauthority | Details → |
| Filename | zabbix_agent.service | Details → |