News

Fire Ant moves from hypervisors onto Cisco routers

Sygnia's incident-response report says the actor it tracks as Fire Ant expanded from hypervisors onto Cisco IOS XR routers, TACACS servers and Linux hosts, turning them into covert collection points. Sygnia assesses the tradecraft strongly overlaps China-nexus UNC3886, not a confirmed identity.

Fire Ant moves from hypervisors onto Cisco routers

Sygnia has published an incident-response report saying the actor it tracks as Fire Ant has pushed beyond hypervisors into the trusted network layer, compromising Cisco IOS XR routers, TACACS authentication servers and Linux management hosts inside an investigated environment. Hold the attribution loosely: Sygnia assesses the activity "strongly overlaps" public Mandiant and Google Cloud reporting on the China-nexus cluster UNC3886, which is an overlap of tradecraft, not a confirmed identity, and this is one environment under investigation, not a proven global campaign.

Name the instrument

This is a vendor forensics report, not a CVE, a CISA advisory, or ransomware. There is no patch to apply, because nothing here turns on a single vulnerability. The investigation began with a tell that only shows up if you are looking: a GRE tunnel interface running on a Cisco IOS XR router with no matching entry in the running configuration and no commit history to explain how it got there. From that tunnel, Sygnia unwound a toolkit built for the router's control plane rather than a generic Linux-on-appliance implant.

The router was rebuilt to lie

The persistence is patient. A boot-themed script at /etc/rc.d/init.d/grub-rommon launches an implant at /usr/bin/acpid, but only during odd-numbered hours, stopping it on even hours to thin out the actor's footprint during routine inspection. The acpid component loads a modified IOS XR syslog library that drops log messages unless they contain the string "Health," so normal telemetry keeps flowing while the actor's own activity is filtered out. Another binary appends an IOS-style exclude filter to show commands so the tunnel configuration never appears when an administrator lists it. Packet captures pulled from the routers were shipped to an external FTP service. The router, in other words, was turned into a collection point that hides its own configuration and edits what its logs say.

The credential layer and the 0xEF tell

On the TACACS servers, a toolset Sygnia calls TacTap injects a library, libseconfd.so, into the running tac_plus process, intercepts accepted authentication sessions by handing their file descriptors through a UNIX socket, and writes the captured credentials to /var/log/.tacplus.acct, obfuscated with a single-byte XOR key of 0xEF. That key is the forensic thread: Mandiant previously documented UNC3886 TACACS tooling XORing credential logs with the same 0xEF. Sygnia adds that this specific tac_plus library-injection technique "has not been publicly described before," which is why the report reads as an evolution of known tradecraft rather than a repeat of it. On the Linux side of the GRE tunnel, a backdoor named BridgeAgent masquerades as zabbix_agent, a hair off the legitimate daemon name zabbix_agentd, and runs as root under a systemd unit while faking its process name as gnome-shell. The Hacker News notes Mandiant had earlier tied the cluster to a TACACS+ sniffer and a backdoored tac_plus daemon, which is the lineage this new library injection extends.

What to hunt now

Do not wait for a signature. Sweep IOS XR devices for GRE or tunnel interfaces that have no matching commit history, and for show-command output that quietly excludes configuration blocks. On TACACS servers, look for injected libraries in tac_plus and for accounting files under dot-prefixed paths. On Linux management hosts, alert on a zabbix_agent process where you expect zabbix_agentd, and on any implant that runs only during odd-numbered hours. For related infrastructure-abuse coverage, see the GoCaracal Ethereum command-and-control write-up, the CISA Siemens S7 advisory, and the OpenAI collective cyber-defense letter.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free