Sygnia found that Fire Ant shifted from VMware hypervisors to Cisco routers, TACACS servers, and Linux management hosts, using a hidden GRE tunnel and custom malware to maintain persistence and spy on traffic. The group also deployed a disguised backdoor called BridgeAgent, abused trusted infrastructure to reach high-value networks, and overlaps with the Chinese espionage group UNC3886. #FireAnt #BridgeAgent #UNC3886 #CiscoIOSXR
Keypoints
- Fire Ant moved from VMware targets to Cisco routers and related management systems.
- A hidden GRE tunnel was found on a Cisco IOS XR router with no matching config history.
- Custom malware suppressed logs, created fake persistence, and enabled covert Telnet access.
- The attackers captured router traffic and used it to map internal topology and authentication flows.
- Sygnia uncovered BridgeAgent, a disguised Zabbix backdoor with TLS reverse shells and payload execution.