{"id":18280,"date":"2026-08-31T11:27:53","date_gmt":"2026-08-31T11:27:53","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18280"},"modified":"2026-08-31T11:27:53","modified_gmt":"2026-08-31T11:27:53","slug":"china-linked-fireplace-ant-hijacks-cisco-routers-to-steal-credentials-and-blind-safety-logs","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18280","title":{"rendered":"China-Linked Fireplace Ant Hijacks Cisco Routers to Steal Credentials and Blind Safety Logs"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjxYI5Ntk3CPoEGUHNQbd80hij-0QLnz3V_HBU3aXV-mvQq98IE6xsRlbuwZ2PNbbSV7dA-HlNfqRWj0_bd3XpQCOPt9R2gS3PJMm8lfMP_9IoKyhDNbY9NOotNDHO68v2DSUT_R-0UYTqZQc16DJM7OqS8_35iVUMqyy3GrUt7iMaIWz6iW6OSP2ddiDc\/s1600\/cisco-creds.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjxYI5Ntk3CPoEGUHNQbd80hij-0QLnz3V_HBU3aXV-mvQq98IE6xsRlbuwZ2PNbbSV7dA-HlNfqRWj0_bd3XpQCOPt9R2gS3PJMm8lfMP_9IoKyhDNbY9NOotNDHO68v2DSUT_R-0UYTqZQc16DJM7OqS8_35iVUMqyy3GrUt7iMaIWz6iW6OSP2ddiDc\/s1600\/cisco-creds.jpg\"\/><\/a><\/div>\n<p>A China-nexus cyber espionage actor tracked as<strong> Fireplace Ant<\/strong> has expanded a long-running marketing campaign past VMware hypervisors to compromise Cisco IOS XR routers, Terminal Entry Controller Entry-Management System (TACACS) servers, and Linux administration hosts used to route, authenticate, and handle high-value networks.<\/p>\n<p>Sygnia, the incident response agency that investigated the intrusion, stated the actor turned the compromised routers into assortment platforms, capturing community visitors, harvesting credentials, and suppressing the logging and telemetry that defenders depend on to reconstruct an assault.<\/p>\n<p>The agency assessed that the hacker group used its foothold to discover paths to linked high-value environments, together with important infrastructure. Nonetheless, exercise towards these networks was restricted to scanning and connection makes an attempt relatively than confirmed compromise.<\/p>\n<p>Controlling the routers gave the actor a vantage level over visitors shifting by way of trusted community paths, Sygnia stated.<\/p>\n<p>&#8220;This exercise reinforces one of many core observations from the investigation: when a menace actor controls routers, they don&#8217;t solely achieve attain. They achieve perspective,&#8221; the agency stated.<\/p>\n<p>The agency assessed that the exercise strongly overlaps with\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/02\/china-linked-unc3886-targets-singapore.html\" target=\"_blank\">public reporting on UNC3886<\/a>, a China-nexus espionage group recognized for concentrating on virtualization platforms and community edge units, although it stated in\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.sygnia.co\/blog\/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure\/\" target=\"_blank\">its report<\/a>\u00a0that it doesn&#8217;t make a conclusive attribution.<\/p>\n<p><!--adsense--><\/p>\n<p>Mandiant, which first documented UNC3886, has stated it\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/china-nexus-espionage-targets-juniper-routers\" target=\"_blank\">discovered no technical overlap<\/a>\u00a0between the group and the separate Chinese language operations tracked as Salt Hurricane and Volt Hurricane.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"more\"\/><\/p>\n<p>The 2026 exercise follows\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/07\/fire-ant-exploits-vmware-flaw-to.html\" target=\"_blank\">Sygnia&#8217;s July 2025 disclosure<\/a>\u00a0of Fireplace Ant, which detailed the group&#8217;s exploitation of VMware ESXi and vCenter environments earlier than shifting into the community and administration layers.<\/p>\n<p>The investigation started with an anomaly on a Cisco IOS XR router, the place a Generic Routing Encapsulation (GRE) tunnel interface was working with no operating configuration or commit historical past to elucidate the way it had been created. Sygnia didn&#8217;t establish how the actor first gained entry to the router.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhuRD9dBO8I1dB7DhtLLjlj-2Dirhi0Ktx0IwvFELrdxuVvW7SwjHIB8prpVAe9D5nUoW5Dj_2wAgZGQ1y9knq7osYyV5XLyFbO-kMPuIiTr0rDSBD0YvQxuxGtaTbETSl44lSq7TCfgLJYTL4Jnl3l3kN3pz_Gx3B709XK45qG6TgtMKRdwmb15PdHnzc\/s1600\/target.png\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"399\" data-original-width=\"1050\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhuRD9dBO8I1dB7DhtLLjlj-2Dirhi0Ktx0IwvFELrdxuVvW7SwjHIB8prpVAe9D5nUoW5Dj_2wAgZGQ1y9knq7osYyV5XLyFbO-kMPuIiTr0rDSBD0YvQxuxGtaTbETSl44lSq7TCfgLJYTL4Jnl3l3kN3pz_Gx3B709XK45qG6TgtMKRdwmb15PdHnzc\/s1600\/target.png\"\/><\/a><\/div>\n<p>Tracing the tunnel led investigators to a legacy Linux system, from which Fireplace Ant ran repeated connection makes an attempt and port probing towards administrative and repair ports on linked networks, together with SSH, HTTP, SMB, and RDP.<\/p>\n<p>The router malware was purpose-built for the IOS XR management airplane relatively than a generic Linux equipment. One part embedded a modified system library that checked every outgoing log message for the string\u00a0Well being\u00a0and forwarded it solely when the string was current.<\/p>\n<p>A separate part altered the router&#8217;s command-execution path to append an\u00a0| exclude\u00a0filter to\u00a0present\u00a0instructions, hiding the attacker&#8217;s tunnel configuration from directors inspecting the machine.<\/p>\n<p>Fireplace Ant then used the routers to seize packet captures (PCAPs) from a number of Cisco units. The captures have been uploaded to exterior FTP servers, certainly one of which appeared to have been put in the identical day the uploads happened.<\/p>\n<p>On the TACACS server, Sygnia recognized a credential-collection toolset it tracks as TacTap.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhVOxqvxfh_6YAxLk4LeYW4_dtqrv7a44AZj10eKJVZlEm1oNCzxe5zWe_0_8PZfM1ngMvglGbZxorRoVA0EUdd8XnFP4u9ubOBemr7_inOB_3bR-JDZuHoEgzabQpXOkHJYxX5EXF-duODGDEcJtnqBziXYVvyBh8zr3w81KIDu8pBD4NNvlb6uQGIJy4\/s1600\/TACACS.png\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"421\" data-original-width=\"1024\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhVOxqvxfh_6YAxLk4LeYW4_dtqrv7a44AZj10eKJVZlEm1oNCzxe5zWe_0_8PZfM1ngMvglGbZxorRoVA0EUdd8XnFP4u9ubOBemr7_inOB_3bR-JDZuHoEgzabQpXOkHJYxX5EXF-duODGDEcJtnqBziXYVvyBh8zr3w81KIDu8pBD4NNvlb6uQGIJy4\/s1600\/TACACS.png\"\/><\/a><\/div>\n<p>An injector named\u00a0acppid\u00a0loaded a malicious library into the operating\u00a0tac_plus\u00a0authentication course of. The library hooked the features that settle for new connections. It then handed the reside session handles to a second course of over an area Unix socket.<\/p>\n<p>The captured credentials have been written to\u00a0\/var\/log\/.tacplus.acct\u00a0and flippantly obfuscated with a single-byte XOR key of\u00a00xEF.<\/p>\n<p>&#8220;To our data, this particular tac_plus library-injection approach has not been publicly described earlier than, making it a notable evolution of Fireplace Ant&#8217;s TACACS-focused credential assortment tradecraft,&#8221; Sygnia stated.<\/p>\n<p>Credential theft from TACACS servers is established tradecraft for the cluster, as Mandiant has beforehand documented UNC3886 deploying a\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/06\/chinese-cyber-espionage-group-exploits.html\" target=\"_blank\">TACACS+ sniffer known as LOOKOVER<\/a>\u00a0and changing the\u00a0tac_plus\u00a0daemon with a backdoored model to log credentials.<\/p>\n<p>Sygnia additionally recovered a second new instrument, a Linux backdoor it known as <strong>BridgeAgent<\/strong>, which was deployed on the tunnel-connected host and masqueraded as a Zabbix monitoring agent.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi27aDUo3N5hyphenhyphenLG4v4UTzKkA0s_GJO1dusNQBDtaWikcP_U-bBErVv-cNRCaOAo6u3TDUTpwvlkc0VSJYnjOu0Prj3JnwXpgMgahG_k0Au3jAu-N9-sf7Y8TDpxiu3PiMsdOhKRsA1XHSiTZiekjJDy1y5uREAt4JWli_9qzq0g6hcQlsNQ9U2CDzKSWHM\/s1600\/BridgeAgent.png\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"445\" data-original-width=\"1024\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi27aDUo3N5hyphenhyphenLG4v4UTzKkA0s_GJO1dusNQBDtaWikcP_U-bBErVv-cNRCaOAo6u3TDUTpwvlkc0VSJYnjOu0Prj3JnwXpgMgahG_k0Au3jAu-N9-sf7Y8TDpxiu3PiMsdOhKRsA1XHSiTZiekjJDy1y5uREAt4JWli_9qzq0g6hcQlsNQ9U2CDzKSWHM\/s1600\/BridgeAgent.png\"\/><\/a><\/div>\n<p>The implant persevered by way of a\u00a0zabbix_agent.service\u00a0systemd unit operating as root, disguised its course of as\u00a0\/usr\/bin\/gnome-shell, and polled the attacker&#8217;s infrastructure over TLS on port 443 for instructions and reverse-shell directions.<\/p>\n<p>Throughout the Linux administration hosts, Fireplace Ant constructed a sturdy entry layer utilizing the open-source Medusa and REPTILE rootkits, customized SSH backdoors, and binaries renamed and timestamped to impersonate the SentinelOne and Cybereason endpoint safety brokers.<\/p>\n<p>A number of of those elements have been planted in 2025 and reused for hands-on exercise in 2026. At the least one backdoor stored operating in reminiscence after its file had been deleted from disk, Sygnia stated.<\/p>\n<p>The actor additionally labored to undermine the proof itself by suppressing router logs, SNMP traps, and authentication requests; disabling SELinux on the Linux hosts; rewriting login-history data; and eradicating entries for privileged instructions from system logs.<\/p>\n<p><!--linkads--><\/p>\n<p>Sygnia stated routers, TACACS servers, hypervisors, and soar hosts ought to be handled as first-class forensic belongings, and that investigators ought to validate logs towards reminiscence, disk, community, authentication, and configuration proof relatively than a single telemetry supply.<\/p>\n<p>Sygnia revealed the next indicators of compromise (IoCs) &#8211;<\/p>\n<ul>\n<li><strong>TacTap:<\/strong> the injector <code>\/usr\/sbin\/acppid<\/code> (SHA1 <code>36005f5e4398a1c62a2a9271eddfcc1b44b1ad00<\/code>), the injected library <code>\/lib\/libseconfd.so<\/code> (<code>955cd45a2f6f226a2fdf44b329af1c8dde90cb38<\/code>), and the credential file <code>\/var\/log\/.tacplus.acct<\/code>, decoded with XOR key <code>0xEF<\/code>.<\/li>\n<li><strong>BridgeAgent:<\/strong> persistence by way of a <code>zabbix_agent.service<\/code> systemd unit, encrypted configuration at <code>\/decide\/.ICEauthority<\/code>, and command-and-control (C2) over TLS on port 443.<\/li>\n<li><strong>IOS XR implants:<\/strong> <code>\/usr\/bin\/acpid<\/code> (<code>be6b27f429324a4af05a310d8ec9635e37c68a94<\/code>), <code>\/pkg\/bin\/dhcpd_show_issu_status<\/code> (<code>1682b652a15bde732489f22809b0b7594c228fd3<\/code>), <code>\/pkg\/bin\/hd<\/code> (<code>b149fa3a34bd585e7a674a4fd9538437bd06f514<\/code>), and the persistence script <code>\/and so forth\/rc.d\/init.d\/grub-rommon<\/code>.<\/li>\n<li><strong>VMCI backdoor:<\/strong> <code>\/var\/tmp\/audit<\/code> (<code>13f0c2a598e3aa63856c032a96b110aed963f0e8<\/code>), speaking over VMware Digital Machine Communication Interface (VMCI) sockets.<\/li>\n<li><strong>Packet-triggered backdoor:<\/strong> <code>\/var\/tmp\/ping<\/code> (<code>5ba1242050b5b447052b210788a5a25593d6987d<\/code>), activating on TCP ports 443, 541, 8443, and 10443 and UDP supply port 40443 to vacation spot port 500, triggered by the string <code>sxcdewqaz!@#<\/code>.<\/li>\n<\/ul>\n<p>The corporate&#8217;s full indicator set and YARA guidelines can be found in its report.<\/p>\n<p>The exercise parallels the router and TACACS+ visitors assortment {that a} CISA-led joint advisory <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/08\/salt-typhoon-exploits-cisco-ivanti-palo.html\">attributed to Salt Hurricane<\/a> in August 2025, a separate Chinese language espionage cluster that captured packet information from compromised routers to reap administrator credentials throughout telecommunications networks.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A China-nexus cyber espionage actor tracked as Fireplace Ant has expanded a long-running marketing campaign past VMware hypervisors to compromise Cisco IOS XR routers, Terminal Entry Controller Entry-Management System (TACACS) servers, and Linux administration hosts used to route, authenticate, and handle high-value networks. Sygnia, the incident response agency that investigated the intrusion, stated the actor [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18282,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10389,3866,536,131,483,596,1651,6196,7734,211,1443],"class_list":["post-18280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ant","tag-blind","tag-chinalinked","tag-cisco","tag-credentials","tag-fire","tag-hijacks","tag-logs","tag-routers","tag-security","tag-steal"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18280"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18280\/revisions"}],"predecessor-version":[{"id":18281,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18280\/revisions\/18281"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18282"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}