China-Linked Hackers Hid In Cisco Routers, Stole Administrator Credentials: Report

Authored by Arthur Zhang via The Epoch Times,

A China-linked cyberespionage group compromised Cisco routers and hid its activity from the network administrators who managed them, cybersecurity firm Sygnia said in an Aug. 27 report.

The Cisco logo is displayed in front of Cisco headquarters in San Jose, Calif., on Feb. 9, 2024. Justin Sullivan/Getty Images

The group also recorded traffic moving through the devices and used them to probe other high-value networks, according to the report.

The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment, allowing them to capture administrator credentials, Sygnia said.

Sygnia tracks the group as Fire Ant and describes it as China-nexus. The firm has not publicly tied the hackers to a specific Chinese government agency, nor have they disclosed the affected organizations or countries, and no U.S. victim has been publicly identified.

Cisco on Sept. 2 separately issued a critical security-hardening update for IOS XR, the router operating system involved in Sygnia's investigation. Cisco said the update addresses seven groups of vulnerabilities discovered through internal testing and not known to be actively exploited.

Cisco's advisory does not mention Fire Ant or Sygnia's investigation, and Sygnia did not identify a Cisco vulnerability used in the attacks.

Hackers Hid Activity on Routers

Sygnia began investigating after researchers found a hidden netw