China-linked hackers intensify attacks on Cisco network devices | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


China-linked threat actors have been using a range of methods to compromise some of Cisco’s most widely deployed router models, turning them into an entry point for monitoring and infiltrating organisations.

The activity has been uncovered by Israeli cybersecurity firm Sygnia, which has published a report on a hacking operation known as ‘Fire Ant’.

Its researchers found that the hackers behind the campaign had taken control of network infrastructure and used the compromised systems to gather intelligence and credentials before establishing persistent access and concealing their activity.

The campaign is believed to be linked to a group that Google’s Mandiant unit tracks as UNC3886, which was implicated in a series of attacks against major strategic organisations between 2022 and 2024.

According to Sygnia, the threat actors have changed their modus operandi. Rather than focusing on endpoints, servers or cloud workloads, they are now seeking to compromise the infrastructure that sits between environments: routers, hypervisors, access devices, Linux management hosts and the systems that ‘create trust, reachability and visibility’.

The latest campaign tracked by the Israeli company focuses on attacks targeting Cisco IOS XR routers.

Sygnia first reported on Fire Ant last year, but the group has remained active this year and expanded its operations beyond compromising hypervisors. The organisations affected by the campaign have not been publicly identified.

“When an attacker controls the routers, they gain not only reach, but also perspective,” the researchers explained.

“Fire Ant used network infrastructure to observe the environment from within, gathering information that could support lateral movement, credential targeting and the planning of access across the network,” they added.

Cisco routers remain a recurring target

Governments and cybersecurity companies have long warned about attacks by groups linked to the Chinese state against Cisco firewalls and routers, according to The Record Media.

In 2024, Volt Typhoon –a cyberespionage group associated with the Chinese government and blamed for several major attacks against US critical infrastructure organisations– was found to have targeted outdated routers and networking equipment made by the US company in the United States, the United Kingdom and Australia.

A year later, researchers and security experts said that more than 1,000 Cisco network devices had been attacked by China-linked actors as part of the campaign known as Salt Typhoon.

In addition, between September and December last year, Palo Alto Networks’ Unit 42 and the US federal cybersecurity agency issued several warnings about China-linked attacks targeting Cisco Adaptive Security Appliances (ASA). These devices are widely used by governments and large companies because they consolidate several network security functions into a single appliance.

China-linked threat actors have been using a range of methods to compromise some of Cisco’s most widely deployed router models, turning them into an entry point for monitoring and infiltrating organisations.

The activity has been uncovered by Israeli cybersecurity firm Sygnia, which has published a report on a hacking operation known as ‘Fire Ant’.

Its researchers found that the hackers behind the campaign had taken control of network infrastructure and used the compromised systems to gather intelligence and credentials before establishing persistent access and concealing their activity.

The campaign is believed to be linked to a group that Google’s Mandiant unit tracks as UNC3886, which was implicated in a series of attacks against major strategic organisations between 2022 and 2024.

According to Sygnia, the threat actors have changed their modus operandi. Rather than focusing on endpoints, servers or cloud workloads, they are now seeking to compromise the infrastructure that sits between environments: routers, hypervisors, access devices, Linux management hosts and the systems that ‘create trust, reachability and visibility’.

The latest campaign tracked by the Israeli company focuses on attacks targeting Cisco IOS XR routers.

Sygnia first reported on Fire Ant last year, but the group has remained active this year and expanded its operations beyond compromising hypervisors. The organisations affected by the campaign have not been publicly identified.

“When an attacker controls the routers, they gain not only reach, but also perspective,” the researchers explained.

“Fire Ant used network infrastructure to observe the environment from within, gathering information that could support lateral movement, credential targeting and the planning of access across the network,” they added.

Cisco routers remain a recurring target

Governments and cybersecurity companies have long warned about attacks by groups linked to the Chinese state against Cisco firewalls and routers, according to The Record Media.

In 2024, Volt Typhoon –a cyberespionage group associated with the Chinese government and blamed for several major attacks against US critical infrastructure organisations– was found to have targeted outdated routers and networking equipment made by the US company in the United States, the United Kingdom and Australia.

A year later, researchers and security experts said that more than 1,000 Cisco network devices had been attacked by China-linked actors as part of the campaign known as Salt Typhoon.

In addition, between September and December last year, Palo Alto Networks’ Unit 42 and the US federal cybersecurity agency issued several warnings about China-linked attacks targeting Cisco Adaptive Security Appliances (ASA). These devices are widely used by governments and large companies because they consolidate several network security functions into a single appliance.


——————————————————-


Click Here For The Original Source.