• Cisco routers are being turned into surveillance vantage points t

    From TechnologyDaily@1337:1/100 to All on Tuesday, September 01, 2026 20:15:24
    Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks and it's all thanks to this new malware

    Date:
    Tue, 01 Sep 2026 19:05:00 +0000

    Description:
    Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Sygnia reports Chinalinked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts Compromised routers act as operational platforms Campaign aims at target behind the target, leveraging trust relationships for broader espionage reach Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, its also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers.

    Once they compromise a router , they dont just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders radars. For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of
    malware spoofing legitimate software. Latest Videos From TechRadar Watch full video here: Target behind the target The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a target behind the target scenario:

    This reinforces the target behind the target concept introduced earlier in this report. Fire Ants interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments, Sygnia explained. You may like Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger malware that turns unsecured devices into a malicious proxy botnet US and security allies warn Russian attacks on critical infrastructure are ramping up These popular Tenda routers have an unpatched security backdoor which could give hackers access

    Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously
    observed by Google . However, there are also significant differences which make attribution inconclusive.

    Via BleepingComputer Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/cisco-routers-are-being-turned-into-sur veillance-vantage-points-to-hoover-up-data-on-trusted-networks-and-its-all-tha nks-to-this-new-malware


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)