China-linked threat actor Fire Ant was observed moving from a hypervisor-level compromise into breaching the trusted infrastructure layer that routes, authenticates, connects and manages high-value enterprise networks and critical infrastructure operations. In an Aug. 27 blog post, Sygnia found that Fire Ant moved its long-running campaign from beyond VMware hypervisors to compromising Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts.Phil Wylie, senior consultant and Evangelist at Suzu Labs, said it’s clear these attackers are very methodical: moving from VMware hypervisors to routers and authentication infrastructure shows they are looking for places where they can maintain access, gather intelligence, and stay hidden for long periods of time. “Routers are especially valuable because they sit in a trusted position with visibility into traffic moving across the network,” said Wylie. “If attackers can compromise that infrastructure and manipulate the logs defenders rely on, they can potentially observe credentials and communications while making their activity much harder to detect.”Jason Soroko, senior fellow at Sectigo, said the Fire Ant case matters because the attacker has moved toward the systems that define trust inside a network. Soroko said a compromised router can expose traffic flows and administrative paths. It can also redirect communications and hide evidence.“A compromised TACACS server can expose the credentials used to manage that infrastructure,” said Soroko. “In a critical infrastructure environment, that can give an adversary a detailed map of the network before any operational system is breached."Soroko added that routers, authentication servers, and hypervisors are part of the attack surface: operators should isolate management networks and restrict administrative access. They should also watch for unexplained tunnels, configuration changes, and unusual outbound traffic, said Soroko. “Logs should be sent somewhere the device itself cannot alter them,” said Soroko. “If these systems are compromised, privileged credentials should be rotated and affected devices rebuilt from trusted images.”Roman Sannikov, global research coordinator at iCounter, said it's not simply that the attackers compromised routers or authentication infrastructure, but how deliberately they turned trusted infrastructure into an intelligence collection layer.“Once an adversary controls the systems responsible for routing traffic and authenticating administrators, they can observe how the environment operates, harvest credentials, identify pathways into higher-value targets and, critically, manipulate the evidence defenders depend on to find them,” said Sannikov. “That creates a fundamental problem for traditional detection and response. If you wait for an alert from inside the environment, you are assuming the telemetry itself can still be trusted. Fire Ant was actively working to make sure that wasn’t the case.”Justin Beals, founder and CEO at Strike Graph, explained that Fire Ant has run a similar playbook to the one we've seen with Salt Typhoon, the China-linked group best-known for hacking U.S. telecoms, federal agencies, and critical infrastructure. Beals said when an actor controls the routers, they do not just gain access, they gain perspective on everything moving through that network.“TACACS servers are especially dangerous to lose because they are the authentication backbone,” said Beals. “Once an attacker owns that layer, they are not breaking in anymore. They are logging in.”Beals said the part that should worry every security leader is the log suppression: Fire Ant did not just steal credentials, it edited what defenders could see.“That is a direct attack on your ability to trust your own evidence,” said Beals. “If you cannot verify your logs, you cannot verify your incident response.”Beals said organizations need to start treating routers and TACACS servers as first-class assets in their security program, not just plumbing: that means continuous validation of configuration and log integrity, not a once-a-year review.“Nation-state actors are patient,” said Beals. “They will sit in network infrastructure for over a year before using it. The only defense is verifying your environment constantly, not periodically."
Critical Infrastructure Security, Network Security, Firewalls, Routers
China-linked campaign targets high-value networks, critical infrastructure
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds