CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5396

As cited

Copy frozen at (site build).

threat intel

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-nexus group tracked as Fire Ant compromised Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts to intercept credentials and disable audit trails in enterprise networks. The campaign, investigated by incident response firm Sygnia, extends the actor's prior focus on VMware hypervisors to network infrastructure.

Why it matters: Network operators and enterprises with Cisco routers and TACACS authentication systems face credential theft and log suppression that could enable persistent, undetected access; defenders should audit router configurations and authentication logs for signs of compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-linked cyber espionage group called Fire Ant has expanded its attack operations to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. Sygnia's investigation revealed the actor broadened its scope beyond previous VMware hypervisor compromises to gain control over critical network infrastructure used for routing, authentication, and management.

Why it matters: Organizations running Cisco IOS XR routers and TACACS-based authentication systems face credential theft and log tampering by a persistent nation-state adversary, requiring immediate review of network device access controls and authentication server integrity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-linked cyber espionage group called Fire Ant has expanded its attack operations to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. Sygnia's investigation revealed the actor broadened its scope beyond previous VMware hypervisor compromises to gain control over critical network infrastructure used for routing, authentication, and management.

Why it matters: Organizations running Cisco IOS XR routers and TACACS-based authentication systems face credential theft and log tampering by a persistent nation-state adversary, requiring immediate review of network device access controls and authentication server integrity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-linked cyber espionage group called Fire Ant has expanded its attack operations to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. Sygnia's investigation revealed the actor broadened its scope beyond previous VMware hypervisor compromises to gain control over critical network infrastructure used for routing, authentication, and management.

Why it matters: Organizations running Cisco IOS XR routers and TACACS-based authentication systems face credential theft and log tampering by a persistent nation-state adversary, requiring immediate review of network device access controls and authentication server integrity.

VendorsAppleCiscoVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary