China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
ID: e0fdca8e-ca56-5260-8806-b98ddd85d1e4
STIX ID: report--e0fdca8e-ca56-5260-8806-b98ddd85d1e4
Feed Name: The Hacker News
Sygnia attributed a sophisticated China-nexus espionage campaign (tracked as Fire Ant and linked to public reporting on UNC3886) that escalated from VMware hypervisors into Cisco IOS XR routers, TACACS servers, and Linux management hosts; the actor used purpose-built router implants, a TACACS credential-stealer (TacTap), a Linux backdoor (BridgeAgent), and other rootkits/backdoors to capture packet data, harvest credentials, suppress logging, and maintain long-term access, with a full set of IoCs published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
