Hackers Turn Cisco Routers Into Spy Platforms to Reach Critical Infrastructure

A China-linked threat actor known as Fire Ant has compromised Cisco IOS XR routers and other trusted infrastructure to spy on networks, steal credentials, maintain hidden access, and explore routes toward critical infrastructure.

The campaign shows how attackers can use routers not only to move traffic, but also as surveillance and attack platforms. Investigators discovered an unexplained GRE tunnel interface on a Cisco IOS XR router.

The interface was active, but there was no matching configuration or commit history to explain how it had been created. This suggested that the router’s operational state had been altered while normal administrative records were manipulated or hidden.

Fire Ant deployed several malicious components designed specifically for the IOS XR environment. One implant was placed in a startup path and disguised as a legitimate service.

It launched another component during selected hours, allowing the malware to remain persistent while reducing the chance of being noticed during routine checks.

Cisco Routers Turned Spy

The malware also modified the router’s logging process. It selectively prevented messages from being forwarded, which suppressed important security events.

Another component manipulated command execution and added filters to router output. This could hide tunnel settings, routing details, or other configuration information from administrators.

BridgeAgent execution flow: persistence through zabbix_agent.service, command-line masquerading as /usr/bin/gnome-shell, encrypted configuration stored at /opt/.ICEauthority, periodic HTTPS polling, and outbound TLS reverse-shell capability (Source: sygnia)
BridgeAgent execution flow: persistence through zabbix_agent.service, command-line masquerading as /usr/bin/gnome-shell, encrypted configuration stored at /opt/.ICEauthority, periodic HTTPS polling, and outbound TLS reverse-shell capability (Source: sygnia)

The attackers also used routers to capture network traffic. They generated PCAP files from several router interfaces and uploaded them to external FTP servers.

These packet captures could reveal internal network layouts, authentication activity, management connections, and traffic between connected environments.

By controlling routers, Fire Ant gained both reach and visibility. The devices provided a trusted position from which the attackers could observe network activity and plan movement into other systems.

The GRE tunnel connected the compromised environment to a legacy Linux system. Fire Ant used this host to conduct repeated connection attempts and scan systems associated with high-value and critical infrastructure environments.

The actor reaches BridgeAgent on the legacy Linux server, where a GRE tunnel provides a pivot to the edge router and opens a route into a connected environment (Source: sygnia)
The actor reaches BridgeAgent on the legacy Linux server, where a GRE tunnel provides a pivot to the edge router and opens a route into a connected environment (Source: sygnia)

The scans targeted common services, including SSH, HTTP, HTTPS, SMB, RPC, and RDP. Researchers found a backdoor named zabbixagent, designed to resemble a legitimate monitoring component.

The implant ran as root through a systemd service, stored encrypted configuration data, contacted external infrastructure over HTTPS, and supported reverse-shell access. It also launched additional tools on the Linux host, sygnia said.

Indicators of Compromise (IOCs)

FilenameSHA1Role / Description
bin/atdC164BFC953C66E58B11FC280E69FD43B8F255839Custom SSH backdoor
bin/gdmMedusa-rootkit-related component

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories