State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
North Korean threat actors are expanding their job fraud operations beyond IT roles to target positions in healthcare and sales sectors. These suspected workers, identified through recent investigations, represent an evolving insider threat strategy as part of broader employment-based infiltration campaigns attributed to the DPRK.
Read full article at The Hacker News ↗An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
A Chinese-linked cyber espionage group designated Fire Ant has escalated its operations by compromising Cisco routers and other trusted network infrastructure to gain access to high-value targets. The attackers stole credentials and manipulated logs to conceal their activities while using the compromised infrastructure as a foothold to reach downstream networks. This shift from individual endpoint compromises to infrastructure-level attacks demonstrates an evolution in the group's operational sophistication and capability for persistent network access.
Russian state-aligned hackers from UAC-0099 are embedding malicious prompts in malware to deliberately trigger AI safety guardrails and disrupt AI-assisted malware analysis tools, a technique ESET has dubbed GuardBreaker. The group, which conducts initial-access operations for the GRU-linked Sandworm, uses VBS scripts containing provocative prompts designed to overwhelm AI safety mechanisms and prevent proper analysis of their malicious code. This represents a new adversarial approach where threat actors actively work to subvert the security tools being used to detect their operations.
The China-linked Fire Ant group has expanded its espionage campaign to target Cisco IOS XR routers, TACACS servers, and Linux management hosts used for network routing and authentication. By compromising these infrastructure components, the actor gains the ability to steal credentials and disable security logging, allowing persistent access to high-value networks. This represents a significant escalation from the group's previous focus on VMware hypervisors.