The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history.
According to incident response company Sygnia, the threat actor switched from targeting VMware hypervisors to compromising Cisco routers, TACACS authentication servers, and Linux management hosts.
The researchers discovered Fire Ant's new tactic after finding on a Cisco IOS XR router an active GRE (Generic Routing Encapsulation) tunnel interface that could not be explained by a running configuration or commit history.
Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that ran the implant only during alternating hours.
The malware selectively suppressed syslog messages to hide tunnel-related information from legitimate administrators, established outbound Telnet connections to Fire Ant infrastructure, and supported interactive shell access with no logging.
Fire Ant's evasion tactics
Source: Sygnia
The attackers also used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers.
These captures could expose internal topology, administrative connections, authentication flows, routing relationships, and traffic exchanged with connected networks.
“This behavior shifts the router’s role from a transit device to a collection platform,” Sygnia explains.
... continue reading