Cisco Routers Vulnerable to State-Sponsored Attacks, Critical Infrastructure at Risk
Key Takeaways A sophisticated threat actor, “Fire Ant,” has been observed compromising Cisco IOS XR routers, turning them into platforms for extensive surveillance and lateral movement....
Key Takeaways
- A sophisticated threat actor, “Fire Ant,” has been observed compromising Cisco IOS XR routers, turning them into platforms for extensive surveillance and lateral movement.
- The campaign, active since 2025 and continuing into 2026, targets critical network infrastructure, including routers, Linux management hosts, and TACACS authentication servers.
- Fire Ant employs advanced techniques like creating covert GRE tunnels, manipulating logs and command outputs, and deploying custom backdoors to maintain persistence and evade detection.
- The compromise of these core network devices poses a significant risk, allowing attackers to spy on networks, exfiltrate sensitive data, and gain access to critical infrastructure.
- Organizations must implement comprehensive security measures, including rigorous monitoring of network devices and multi-source forensic investigations, to detect and eradicate this threat.
A persistent and advanced threat actor, dubbed “Fire Ant,” has escalated its operational scope, moving beyond isolated system attacks to infiltrate the very backbone of organizational networks. This group is now actively compromising Cisco IOS XR routers, transforming these crucial network devices into covert platforms for espionage, remote access, and strategic advancement into high-value network segments.
Table Of Content
The current campaign highlights a significant evolution in attacker tactics, demonstrating how a router can be exploited far beyond its traditional role as a simple network gateway. Fire Ant has been observed establishing General Routing Encapsulation (GRE) tunnels that are deliberately hidden from standard running configurations and commit records. This allows them to clandestinely capture network traffic, including packet capture (PCAP) files, and exfiltrate this sensitive data to external FTP services.
According to Sygnia said in a report, the threat actor also actively tampers with system logs and command outputs, creating a deceptive environment where administrators are presented with an incomplete or misleading view of network activity. This sophisticated evasion technique further complicates detection and response efforts.
Sygnia’s analysts initially uncovered this activity while investigating a broader intrusion that spanned across various critical components: network routers, Linux-based management hosts, and TACACS authentication servers. First documented in 2025 and remaining active through 2026, Fire Ant has expanded its focus from virtualized environments (hypervisors) to critical infrastructure responsible for routing, authenticating, and monitoring enterprise operations.
The implications of such a compromise extend far beyond the immediately breached organization. Once inside, Fire Ant leverages the compromised network as a bridge, utilizing Linux systems at the far end of their covert tunnels to probe and access systems associated with critical infrastructure. This mirrors the severe risks associated with other router malware deployments, where control over a network appliance can lead to widespread data exposure and deep penetration into an environment.
Hackers Compromise Cisco Routers
Fire Ant has developed a specialized toolkit designed specifically for the IOS XR control plane. This includes a persistence script located at /etc/rc.d/init.d/grub-rommon, which launches an implant disguised as /usr/bin/acpid on alternating hourly intervals to minimize its visibility. This implant modifies the router’s syslog flow, selectively blocking certain messages from being sent, while another component uses IOS XR routing and Telnet management functions for covert outbound communication.
An additional component manipulates command execution, adding exclusion filters to “show” commands, effectively hiding tunnel-related details from administrators. This combination of tools allows Fire Ant to use the routers for both data concealment and collection. The group captures packets from various router interfaces and uploads this data to external FTP infrastructure. Packet captures are invaluable to attackers, as they can reveal intricate network layouts, connection details, authentication exchanges, and the relationships between systems that security teams might otherwise treat as isolated.
The Sygnia report also detailed the discovery of a Linux host running “BridgeAgent,” a backdoor masquerading as a benign monitoring process. This backdoor stores encrypted configuration settings in /opt/.ICEauthority and communicates with external command-and-control infrastructure over TLS. This Linux host serves as a crucial staging point, facilitating network scanning and providing further access through the established GRE tunnel.
Authentication and Evidence Under Attack
Fire Ant’s operational scope extends to critical authentication services, specifically TACACS, which is responsible for authenticating and logging administrative access to network devices. The group employs a toolset named “TacTap” to inject a malicious library into the tac_plus process. This library intercepts accepted sessions and writes harvested credential material to an obfuscated log artifact. This tactic severely undermines the integrity of audit trails, making it exceptionally difficult to investigate unauthorized access.
On Linux management servers, the actor deploys custom SSH backdoors and components related to the Medusa rootkit, often using filenames designed to resemble legitimate services. They also disable or weaken SELinux, a critical security enhancement, to further their objectives. A packet-triggered backdoor can lie dormant, awaiting specially marked network traffic for activation, while port redirection and IP forwarding are utilized to support covert tunneling operations.
This sophisticated router activity, reminiscent of previous China-nexus router campaigns, underscores the critical importance of treating network device telemetry with the same level of scrutiny as endpoint evidence. Incident responders must recognize routers, authentication systems, hypervisors, jump hosts, and management appliances as fundamental security and forensic assets. Investigations should involve cross-referencing logs with memory, disk, network, authentication, and configuration data, rather than relying on a single source of truth.
What You Should Do
- Immediately investigate any unauthorized GRE interfaces, unexpected router PCAP file creation, or outbound FTP/SCP connections from network devices.
- Scrutinize router command accounting logs for any gaps or suspicious activity, particularly around “show” commands.
- Look for signs of suspicious
tac_plusprocess injection and review TACACS credential artifacts for unusual patterns. - Conduct thorough reviews of external network exposure and segmentation, especially for organizations connected to operational technology (OT) networks. Weak identity and network controls can quickly turn an initial foothold into widespread access.
- Rotate all potentially exposed administrative credentials across all tiers of your infrastructure.
- Restore and verify the integrity of all security controls.
- Prioritize the collection of volatile evidence before any cleanup operations, as Fire Ant employs overlapping persistence mechanisms.
- Execute broad threat hunts across all routers and Linux systems for the provided Indicators of Compromise (IoCs).
- Understand that simply removing a single malicious file is insufficient. Fire Ant’s layered persistence and access paths necessitate a complete, coordinated response across every affected technology layer to ensure full eradication.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.