Chinese Fire Ant hackers turn Cisco routers into spying platforms
Researchers discovered Fire Ant's new tactic of using Cisco routers as spying platforms. The threat actor compromised routers, TACACS servers, and Linux hosts.
Intelligence analysis by Qwen 2.5 (3B)

Chinese hackers, known as Fire Ant, are using Cisco routers as spying platforms, compromising routers, TACACS servers, and Linux hosts. They established GRE tunnels and captured traffic.
Fire Ant hackers are using Cisco routers like spies. They put a secret tunnel in the router and use it to spy on other computers. They also put a special program on the router to hide their tracks.
Analysis
{"heading_1":"Fire Ant's New Tactics","subheading_1":"GRE Tunnel Interface","content_1":"Researchers found an active GRE tunnel interface on a Cisco IOS XR router that could not be explained by the running configuration or commit history. This interface was used to establish a covert communication channel.","subheading_2":"Custom Malware Deployment","content_2":"Fire Ant deployed custom malware on the devices, enabling persistence through a fake system service that ran the implant only during alternating hours. The malware suppressed syslog messages and established outbound Telnet connections to Fire Ant infrastructure.","subheading_3":"Staging and Reconnaissance","content_3":"Fire Ant used a Linux server as a staging and reconnaissance system. The attackers probed systems in connected high-value environments, including critical infrastructure, over commonly used ports like SSH, web services, SMB/RPC, and RDP."}
Key points
- Fire Ant hackers are using Cisco routers as spying platforms
- They compromised routers, TACACS servers, and Linux hosts
- They established GRE tunnels and captured traffic
- Fire Ant used a Linux server as a staging and reconnaissance system
With better security measures, routers can be less vulnerable to such spying.
If Fire Ant continues to use these tactics, they might be able to gather more sensitive information.


