Chinese Hackers Hijack Cisco Routers and TACACS Servers for Long-Term Espionage
A Chinese threat group known as Fire Ant has compromised Cisco IOS XR routers, TACACS+ authentication servers, and Linux management hosts to build persistent espionage infrastructure. The attackers deployed custom malware including BridgeAgent and the TacTap tool to steal TACACS and SSH credentials, enabling them to impersonate legitimate network administrators. They used hidden GRE tunnels, suppressed system logs, and captured network traffic into PCAP files that were exfiltrated to external FTP servers. The campaign targeted management plane infrastructure to gain a foothold for lateral movement toward high-value networks, including critical infrastructure. Security firm Sygnia recommends isolating management planes, cross-validating router states using independent sources, and rebuilding compromised systems from verified clean images.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in