bleeping-computer · Crawled Sep 1, 2026
Chinese Fire Ant hackers turn Cisco routers into spying platforms
1 IoCs 1 Actors
Read original article ↗
AI Summary
The Chinese state-sponsored threat actor Fire Ant has shifted tactics to compromise Cisco IOS XR routers, TACACS servers, and Linux management systems, turning routers into surveillance platforms via concealed GRE tunnels. The group deployed a custom backdoor named 'BridgeAgent', disguised as a Zabbix agent, enabling reverse shells and execution of additional payloads. Fire Ant uses stealthy persistence mechanisms, suppresses syslog messages, and exfiltrates network traffic PCAPs to FTP servers, aiming to map and access high-value networks through a 'target behind the target' strategy. The group's activity overlaps with UNC3886 but shows distinct implementation differences.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | BridgeAgent | Details → |
MITRE ATT&CK TTPs 25 techniques
T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1040 Network Sniffing · Credential Access T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1070.006 Timestomp · Defense Evasion T1071.001 Web Protocols · Command And Control T1078.002 Domain Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098.002 Additional Email Delegate Permissions · Persistence T1105 Ingress Tool Transfer · Command And Control T1110.001 Password Guessing · Credential Access T1136.001 Local Account · Persistence T1543.001 Launch Agent · Persistence T1556.004 Network Device Authentication · Credential Access T1566 Phishing · Initial Access T1573.004 T1573.004 T1583 Acquire Infrastructure · Resource Development T1588 Obtain Capabilities · Resource Development