- This topic has 0 replies, 1 voice, and was last updated 6 days, 5 hours ago by
Phillip Beall (W5EBC).
-
AuthorPosts
-
September 3, 2026 at 7:57 am #49577
All,
This one caught my attention because there is a lesson here that extends well beyond the large corporate and government networks that were apparently being targeted.Cybersecurity researchers have uncovered a sophisticated China-linked espionage operation in which hackers compromised Cisco routers and other network-management infrastructure, then used that equipment not simply as a target, but as a place from which to watch and attack the rest of the network.
The group, which cybersecurity firm Sygnia calls “Fire Ant,” compromised Cisco IOS XR routers, TACACS administrator-authentication systems and Linux management servers.
Once inside, the attackers were reportedly able to capture network traffic, steal administrator credentials, establish covert connections and hide evidence of what they were doing.
That last part is particularly interesting.
Investigators found malware capable of suppressing router logs and SNMP alerts and even manipulating the results of commands administrators used to examine the router. In one case, investigators discovered an operating GRE tunnel that could not be explained by the router configuration or configuration history they were seeing.
In other words, the attackers weren’t merely compromising the network. They were compromising some of the very tools the network administrators would normally use to determine whether the network had been compromised.
The attackers also went after TACACS infrastructure, which large organizations use to authenticate people administering routers and other network equipment. Malware placed in that authentication path allowed them to collect administrator credential information, potentially giving them access to still more equipment.
A qualification is important: this report concerns sophisticated attacks against Cisco IOS XR equipment and large, high-value networks. It does not mean that everybody with a Cisco or Linksys Wi-Fi router at home has been compromised.
So why post it here?
Because amateur radio is becoming increasingly network dependent.
Many of us now have Raspberry Pis, hotspots, AllStar nodes, cameras, weather equipment, SDRs, remote-station computers, antenna controllers, Meshtastic equipment, home-automation devices and even radios themselves connected to our home networks or reachable remotely.
And hams are probably as guilty as anybody of getting a piece of equipment working and then leaving it configured exactly that way for years.
The practical reminders are pretty simple:
- Don’t expose equipment-management pages directly to the Internet unless there is a compelling reason.
- Change default usernames and passwords.
- Use strong, unique passwords rather than reusing the same administrator password on several devices.
- Keep router, firewall and device firmware reasonably current.
- Disable services and remote-management features you don’t use.
- Use SSH, VPNs and other encrypted methods rather than old unencrypted management protocols where possible.
- Consider putting Internet-connected radio, IoT and experimental equipment on a separate network or VLAN from computers containing important personal information.
- Keep backups of important configurations so you know what the equipment should look like.
The larger lesson may be the most interesting one: your router isn’t merely the door to your network. If somebody takes control of it, it can become a very good seat from which to watch everything happening inside.
Article:
China-Linked Hackers Hid in Cisco Routers, Stole Administrator Credentials: Report — The Epoch TimesArchived copy:
Archive.is copy73
Phillip Beall (W5EBC) -
AuthorPosts
- You must be logged in to reply to this topic.