Fire Ant Hackers Infiltrate Cisco Routers for Spy Network

The compromised units were in critical infrastructure and government offices across the Asia‑Pacific, letting Fire Ant harvest significant data over long periods.

Sygnia uncovered the campaign after spotting anomalous command‑and‑control callbacks. The investigation, cited by The Epoch Times, shows Fire Ant implanted malware, used router ACLs to mask traffic, and leveraged the compromised devices as launch pads to probe enterprise networks for further footholds. Additionally, Fire Ant used encryption to obfuscate its traffic, making detection by signature‑based tools difficult, and they rotated keys to avoid pattern‑based alerts. The group also created backdoor SSH sessions for commands and data theft, hiding traffic inside legitimate protocol flows to avoid detection. Moreover, Fire Ant’s malware survived firmware upgrades by re‑injecting into config files, keeping persistence during reboots.

The breach shows routers are espionage targets. Firms should patch firmware, audit configurations, adopt zero‑trust networking, and use telemetry to spot hidden activity before lateral moves.

Source: Read original article

By AI