Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and…

https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1920-80.jpg
  • Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts
  • Compromised routers act as operational platforms
  • Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach

Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers.

Once they compromise a router, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars.

For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more