China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
China-linked cyber espionage group, Fire Ant, has expanded its campaign beyond VMware to compromise Cisco routers and TACACS servers, leveraging a sophisticated toolkit to steal credentials and suppress logging. The group uses a layered approach, including custom Linux backdoors, rootkits, and tools like TacTap to inject malicious libraries and collect data. They actively work to undermine evidence by suppressing logs and manipulating system configurations. This activity mirrors a previous campaign attributed to Salt Typhoon, highlighting a persistent threat targeting telecommunications infrastructure.
A China-nexus cyber espionage group, tracked as Fire Ant, has significantly broadened its attack scope, moving beyond virtualization platforms to actively target Cisco routers and TACACS servers. Sygnia, a response firm, discovered that Fire Ant is now utilizing a comprehensive suite of tools to steal credentials and actively suppress logging and telemetry, hindering defensive efforts. The group’s strategy involves deploying custom Linux backdoors, such as BridgeAgent, disguised as Zabbix agents, and leveraging rootkits like Medusa and REPTILE to establish durable access layers.
Fire Ant employs a sophisticated toolkit, including the TacTap injector, which injects a malicious library into the tac_plus authentication process, and the Packet-triggered backdoor, which activates on specific TCP and UDP ports. The group also actively works to undermine evidence by suppressing router logs, SNMP traps, and authentication requests, rewriting login history records, and removing entries for privileged commands from system logs.
Tracing the initial compromise, Sygnia identified a Generic Routing Encapsulation (GRE) tunnel interface on a Cisco IOS XR router with no configuration history, leading to a legacy Linux system from which Fire Ant initiated connection attempts and port probing against administrative and service ports, including SSH, HTTP, SMB, and RDP. The activity closely parallels a CISA-led joint advisory from August 2025, which attributed similar router and TACACS+ traffic collection to Salt Typhoon, another Chinese espionage cluster targeting telecommunications networks. Indicators of compromise (IOCs) include TacTap, BridgeAgent, and various router and Linux implants. The company’s full indicator set and YARA rules are available in its report.
