A China-linked cyber espionage group tracked as Fire Ant has expanded its campaign beyond VMware hypervisors to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. The threat actor aims to steal credentials and disable security logging on high-value networks. Incident response firm Sygnia investigated the intrusion and attributed it to Fire Ant. The campaign targets critical network infrastructure used for routing, authentication, and management. The expansion of attack surface suggests an evolving and sophisticated threat actor with persistent access objectives. TACACS server compromise enables credential theft at scale across managed network devices. Blinding security logs indicates deliberate operational security measures to evade detection. The campaign reflects broader Chinese cyber espionage interest in telecommunications and enterprise network infrastructure.
Fire Ant (strongly overlapping with UNC3886) expanded its campaign from VMware hypervisors to Cisco IOS XR routers, TACACS servers, and Linux management hosts. The attack began with an unexplained GRE tunnel interface on a Cisco IOS XR router with no commit history. From a legacy Linux system connected via the tunnel, the actor performed port scanning and connection attempts against SSH, HTTP, SMB, and RDP. On the router, purpose-built IOS XR malware was deployed: one component modified a system library to filter log messages, only forwarding those containing the string 'Health', effectively suppressing most logging; another modified the command-execution path to append '| exclude' filters to 'show' commands, hiding tunnel configuration from administrators. Packet captures (PCAPs) were taken from multiple Cisco devices and exfiltrated to external FTP servers. On TACACS servers, a credential-collection toolset called TacTap was deployed: an injector named 'acppid' loaded a malicious library into the running tac_plus authentication process, hooking functions that accept new connections and passing session handles to a second process via a local Unix socket. Captured credentials were written to /var/log/.tacplus.acct and obfuscated with XOR key 0xEF. A new Linux backdoor called BridgeAgent was deployed, masquerading as a Zabbix monitoring agent, persisting via a zabbix_agent.service systemd unit running as root, disguising its process as /usr/bin/gnome-shell, and polling C2 infrastructure over TLS on port 443. On Linux management hosts, the actor used open-source Medusa and REPTILE rootkits, custom SSH backdoors, and binaries renamed and timestamped to impersonate SentinelOne and Cybereason endpoint agents. At least one backdoor continued running in memory after its on-disk file was deleted. The actor also suppressed router logs, SNMP traps, and authentication requests; disabled SELinux on Linux hosts; rewrote login-history records; and removed privileged command entries from system logs. A VMCI backdoor communicated over VMware Virtual Machine Communication Interface sockets, and a packet-triggered backdoor activated on specific TCP/UDP ports triggered by the string 'sxcdewqaz!@#'.
1. Treat routers, TACACS servers, hypervisors, and jump hosts as first-class forensic assets. 2. Validate logs against memory, disk, network, authentication, and configuration evidence rather than relying on a single telemetry source. 3. Inspect Cisco IOS XR router configurations for unexplained GRE tunnel interfaces with no commit history. 4. Check for unauthorized or modified system libraries on TACACS servers, particularly /lib/libseconfd.so, and unusual processes such as acppid. 5. Monitor for credential output files such as /var/log/.tacplus.acct. 6. Review systemd unit files for suspicious services masquerading as legitimate monitoring agents (e.g., zabbix_agent.service running as root). 7. Audit Linux hosts for the presence of Medusa and REPTILE rootkits, custom SSH backdoors, and binaries impersonating security agent executables (SentinelOne, Cybereason). 8. Ensure SELinux is enabled on Linux management hosts and monitor for attempts to disable it. 9. Review login history records and system logs for signs of tampering or deletion of privileged command entries. 10. Monitor for PCAP capture activity and unexpected FTP upload connections from network devices. 11. Check IOS XR show command outputs for appended exclude filters that could hide attacker configurations. 12. Monitor SNMP trap suppression and unusual authentication request drops. 13. Hunt for the published IoCs including SHA1 hashes, file paths, network indicators, and the packet-trigger string 'sxcdewqaz!@#'. 14. Apply Sygnia's published YARA rules and full IoC set from their report. 15. Segment administrative and management networks to limit lateral movement from compromised routers to critical infrastructure.
[object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object], [object Object]