Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware
Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones.
Cybersecurity researchers have found that the China-linked Fire Ant cyberespionage group is now targeting routers, authentication systems, and Linux management hosts. Compromised routers are being transformed into full-fledged operational platforms to collect traffic, manipulate command output, and suppress logging. Fire Ant has also been seen targeting TACACS servers to harvest credentials and weaken audit logs.
The goal of the campaign is to establish a "target behind the target," leveraging trust relationships to gain broader espionage reach.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.