China-Linked Fire Ant Group Compromises Cisco Routers
The Fire Ant cyberespionage group used TacTap malware to steal administrator credentials from Cisco routers to probe critical infrastructure networks.
A China-linked cyberespionage group known as Fire Ant compromised Cisco routers to steal administrator credentials and monitor network traffic. According to a report from cybersecurity firm Sygnia, the group deployed a tool called TacTap to embed malware within the Terminal Access Controller Access-Control System login verification process. This allowed the attackers to capture credentials during administrator sign-ins while suppressing router logs to hide their presence.
Sygnia described the group's strategy as targeting a "target behind the target," using the compromised routers as jumping-off points to probe other high-value networks, including critical infrastructure. The report did not identify a specific Cisco vulnerability used in the attacks, nor were any U.S. victims or affected countries publicly disclosed.
In response to internal testing, Cisco issued a security-hardening update for its IOS XR operating system on September 2 to address seven groups of vulnerabilities. The company did not mention Fire Ant in its advisory. The Cybersecurity & Infrastructure Security Agency declined to comment on the findings.