Hackers forced Cisco to hide its own hack. Magazines and teams can no longer be considered true

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
464
Reaction score
748
Deposit
0$
Cisco routers, which administrators trusted to manage the network and event logs, themselves became a surveillance tool. The China-affiliated Fire Ant cluster captured devices running Cisco IOS XR, intercepted traffic through them, stole credentials and at the same time hid its own activity from defenders.





The investigation began with a strange detail. One router had a GRE tunnel that was neither in the current configuration nor in the history of change. Further analysis showed that the attackers could change the very representation of the device about their own configuration, so the standard commands of the administrator no longer reflected the real state of the system.





For Cisco IOS XR, the attackers have prepared a specialized set of components. The acpid implant interfered with system logging and selectively blocked messages, and a separate module changed the processing of show commands and automatically added filters that concealed information about the malicious tunnel. Another component supported outgoing Telnet connections to the operator infrastructure. To reduce visibility, the acpid was launched in odd hours and stopped in even.





The captured routers have become full-fledged intelligence-gathering points. Fire Ant created network traffic dumps on multiple Cisco devices and sent PCAP files to external FTP servers. Such access allowed to see the internal topology, administrative connections, routes and flows between the connected networks much wider than when the individual server is compromised.












The next goal was the TACACS+ infrastructure, through which organizations check administrative credentials and record the actions of operators. The TacTap tool implemented the malicious library directly into the tac_plus process, intercepted new sessions, and stored stolen login data. After such compromise, it was no longer possible to trust authentication logs without additional verification.





On the Linux control hosts, Fire Ant deployed BridgeAgent, its own SSH backdoors, Medusa components, and a program that remained idle until a specially formed network package was received. The attackers disabled SELinux, changed the rules of iptables, replaced the entry records and masked malicious processes under legitimate protective software.





Sygnia sees strong similarities between Fire Ant and Chinese spy group UNC3886, which previously attacked VMware, Fortinet and network infrastructure. However, the company speaks precisely about the intersection of methods and tools, and not about the proven complete coincidence of groups. The main purpose of the campaign is wider than the usual consolidation within one company. Control over routers, authentication systems, and control servers created a convenient point for reconnaissance of connected networks, including high-value infrastructure.





Specialists are advised to consider routers and other control nodes as full-fledged objects of digital forensics. Cisco publishes the IOS XR analysis procedure separately. In the case of Fire Ant, one check of the logs is not enough, as the attackers purposefully changed the sources of telemetry themselves. The state of the devices has to be checked with memory, disks, network traffic, configuration and external logs.
 
Top Bottom