Fire Ant Shifts Tactics, Weaponizing Cisco Routers for Covert Surveillance
A sophisticated threat actor, dubbed **Fire Ant**, has evolved its attack methodologies, moving from targeting **VMware** hypervisors to compromising **Cisco** routers, **TACACS** authentication servers, and **Linux** management hosts. This strategic shift transforms network infrastructure into covert surveillance platforms, enabling deep reconnaissance and lateral movement into high-value environments.
Cybersecurity firm **Sygnia** has uncovered a significant evolution in the tactics of the **Fire Ant** threat actor. Researchers identified an unexplained active **GRE** (Generic Routing Encapsulation) tunnel interface on a **Cisco IOS XR** router, signaling a new, stealthy approach to network compromise.

### Stealthy Infiltration and Persistence
Further investigation revealed that **Fire Ant** deployed custom malware on these devices. This malware ensures persistence by masquerading as a fake system service, operating only during alternating hours to evade detection. Its sophisticated evasion tactics include selectively suppressing syslog messages to hide tunnel-related information from administrators and establishing outbound **Telnet** connections to **Fire Ant** infrastructure, all while supporting interactive shell access with no logging.

### Routers as Collection Platforms
Beyond establishing persistence, the attackers leveraged administrative access to capture traffic from multiple routers. The resulting **PCAP** files were then uploaded to external **FTP** servers. This data could expose critical network details, including internal topology, administrative connections, authentication flows, routing relationships, and traffic exchanged with connected networks.
As **Sygnia** explains, this behavior fundamentally shifts the router's role: βOnce the actor controlled the router, the device became a vantage point for observing traffic moving through trusted network paths.β
### The 'Target Behind the Target' Strategy
The concealed **GRE** tunnel linked a compromised router to a legacy **Linux** server, which **Fire Ant** utilized as a staging and reconnaissance system. From this vantage point, attackers probed systems in connected high-value environments, including those associated with critical infrastructure. This probing targeted common ports for **SSH**, web services, **SMB/RPC**, and **RDP**.
**Sygnia** posits that **Fire Ant**'s objective is to compromise trusted infrastructure at an initial victim, using it as a covert bridge to explore access paths into connected high-value networks β a tactic they term βtarget behind the target.β
.jpg)
### Discovering 'BridgeAgent'
The researchers also uncovered a previously undocumented backdoor named β**BridgeAgent**β, cunningly disguised as a legitimate **Zabbix** monitoring agent. This backdoor achieves root-level systemd service persistence and facilitates **TLS** reverse shells and the execution of additional payloads on compromised hosts.
.jpg)
### Overlap with UNC3886 and Detection Warnings
While **Fire Ant**'s activity shows strong overlap with **UNC3886**, a Chinese espionage group previously documented by **Google**, **Sygnia** notes differences in filenames, paths, and implementation details. This suggests either an evolution of the group or a distinct, but related, entity.
**Sygnia** warns that **Fire Ant** systematically tampers with system logs and records, even altering file timestamps to obscure evidence. Investigators are advised to validate logs retrieved from compromised infrastructure against other data sources to ensure accuracy.
**Sygnia**'s comprehensive report includes an extensive list of indicators of compromise (**IoCs**), along with hunting and **YARA** rules to aid in detecting **Fire Ant** activity.