Cisco Routers Are Being Used in a Way Security Teams Did Not Expect

The420.in Staff
4 Min Read

A China-linked hacking group known as Fire Ant has allegedly compromised Cisco routers and used them as covert surveillance points inside targeted networks, according to research by incident response company Sygnia. The attackers reportedly relied on custom malware, hidden GRE tunnels and anti-forensic techniques to maintain access, monitor traffic and move towards other connected systems.

How Were Cisco Routers Turned Into Spying Platforms?

Researchers uncovered the activity after finding an active Generic Routing Encapsulation, or GRE, tunnel interface on a Cisco IOS XR router that could not be explained by its normal configuration or commit history.

According to Sygnia, Fire Ant has shifted from targeting VMware hypervisors to compromising Cisco routers, TACACS authentication servers and Linux management hosts.

The compromised routers allegedly gave the attackers a trusted position inside the network, allowing them to observe traffic moving through connected systems.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

What Malware Was Found on the Compromised Devices?

Further analysis found custom malware deployed on affected devices.

The malware allegedly maintained persistence through a fake system service and ran the implant only during alternating hours, a tactic that could make the activity harder to detect.

It also suppressed certain syslog messages linked to the hidden tunnel, helping conceal activity from legitimate administrators.

How Did the Attackers Hide Their Presence?

The attackers allegedly established outbound Telnet connections to Fire Ant infrastructure and supported interactive shell access without logging.

Researchers also found evidence that system logs and file timestamps had been altered to obscure activity that could otherwise help investigators reconstruct the intrusion.

Sygnia warned that logs collected directly from compromised infrastructure should therefore be checked against other sources before being treated as reliable evidence.

What Information Could the Attackers Collect?

After gaining administrative access, the attackers allegedly captured traffic from multiple routers and uploaded the resulting PCAP files to external FTP servers.

Those captures could reveal internal network topology, administrative connections, authentication flows, routing relationships and traffic exchanged with connected networks.

Sygnia said the technique effectively changed the router from a simple transit device into a collection platform for observing traffic moving through trusted network paths.

Were Other High-Value Systems Also Targeted?

The concealed GRE tunnel connected one compromised router to a legacy Linux server that was allegedly used for staging and reconnaissance.

From there, Fire Ant reportedly probed systems in connected high-value environments, including systems associated with critical infrastructure, over ports commonly used for SSH, web services, SMB/RPC and RDP.

Sygnia believes the operation was designed to compromise trusted infrastructure at one organisation and then use that access as a bridge towards other connected high-value targets.

What Is the BridgeAgent Backdoor?

Researchers also discovered a previously undocumented backdoor called BridgeAgent, which Fire Ant allegedly disguised as a legitimate Zabbix monitoring agent.

The backdoor reportedly operates as a root-level system service and supports TLS reverse shells as well as the execution of additional payloads on compromised hosts.

Sygnia said Fire Ant’s activity strongly overlaps with UNC3886, a Chinese espionage group previously documented by Google, although researchers also noted differences in filenames, paths and implementation details.

The findings highlight how compromised network infrastructure can be used not only to gain access, but also to quietly monitor traffic and move deeper into connected environments while attempting to erase traces of the intrusion.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Stay Connected