• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Red River Valley Amateur Radio Club

Amateur Radio in and around the Red River Valley Area of Northeast Texas

  • Home
  • About
    • Contact Us
    • Leadership
  • Membership
    • Member Login
    • The Benefits of Membership
    • Join Us/Renew
    • Profile
    • Member Directory
    • Logout
  • Forums
  • Sponsor
  • Search
  • Ham News
  • History
    • Honor Roll
    • Silent Key
    • Club History
    • Storm Chase 3/25/2019
    • February 2019 Meeting
    • Field Day
      • Field Day 2019
      • Field Day 2005
  • Education/Testing
    • Want to become a ham?
    • Testing – ARRL Volunteer Examiner Administered
    • Current DX Spots
    • APRS® Messaging System
  • Library
    • Meeting Minutes
    • “Unofficial” Call Sign List
    • RRVARC Net Call Up Script
    • Manuals – Operating, Instruction, Literature, Spec Sheets, etc.
    • Band Plan Illustrations
    • Cross Band Repeater Operation – Charles Penry (WA5VHU) – Recommended Best Practices
    • How to obtain an official copy of your FCC license
    • Governing Documents – Approved
    • Club Reports and Recurring Obligations
    • Governance Project
    • RRVARC-WB5RDD INVENTORY LIST
  • Club Repeaters
  • Shop
  • Officers Only
    • Media Contacts
    • Treasurer’s Reports
    • Texas Required Filings
    • Membership Applications
    • Website Management
    • Website Updating – Tips – Tricks
    • Cellular Hot Spots
Home » Topics » Digital Knowledge » China-Linked Hackers Hid in Cisco Routers

China-Linked Hackers Hid in Cisco Routers

  • This topic has 0 replies, 1 voice, and was last updated 6 days, 5 hours ago by Phillip BeallPhillip Beall (W5EBC).
Viewing 1 post (of 1 total)
  • Author
    Posts
  • September 3, 2026 at 7:57 am #49577
    Phillip BeallPhillip Beall (W5EBC)
    Keymaster

      All,

      This one caught my attention because there is a lesson here that extends well beyond the large corporate and government networks that were apparently being targeted.

      Cybersecurity researchers have uncovered a sophisticated China-linked espionage operation in which hackers compromised Cisco routers and other network-management infrastructure, then used that equipment not simply as a target, but as a place from which to watch and attack the rest of the network.

      The group, which cybersecurity firm Sygnia calls “Fire Ant,” compromised Cisco IOS XR routers, TACACS administrator-authentication systems and Linux management servers.

      Once inside, the attackers were reportedly able to capture network traffic, steal administrator credentials, establish covert connections and hide evidence of what they were doing.

      That last part is particularly interesting.

      Investigators found malware capable of suppressing router logs and SNMP alerts and even manipulating the results of commands administrators used to examine the router. In one case, investigators discovered an operating GRE tunnel that could not be explained by the router configuration or configuration history they were seeing.

      In other words, the attackers weren’t merely compromising the network. They were compromising some of the very tools the network administrators would normally use to determine whether the network had been compromised.

      The attackers also went after TACACS infrastructure, which large organizations use to authenticate people administering routers and other network equipment. Malware placed in that authentication path allowed them to collect administrator credential information, potentially giving them access to still more equipment.

      A qualification is important: this report concerns sophisticated attacks against Cisco IOS XR equipment and large, high-value networks. It does not mean that everybody with a Cisco or Linksys Wi-Fi router at home has been compromised.

      So why post it here?

      Because amateur radio is becoming increasingly network dependent.

      Many of us now have Raspberry Pis, hotspots, AllStar nodes, cameras, weather equipment, SDRs, remote-station computers, antenna controllers, Meshtastic equipment, home-automation devices and even radios themselves connected to our home networks or reachable remotely.

      And hams are probably as guilty as anybody of getting a piece of equipment working and then leaving it configured exactly that way for years.

      The practical reminders are pretty simple:

      • Don’t expose equipment-management pages directly to the Internet unless there is a compelling reason.
      • Change default usernames and passwords.
      • Use strong, unique passwords rather than reusing the same administrator password on several devices.
      • Keep router, firewall and device firmware reasonably current.
      • Disable services and remote-management features you don’t use.
      • Use SSH, VPNs and other encrypted methods rather than old unencrypted management protocols where possible.
      • Consider putting Internet-connected radio, IoT and experimental equipment on a separate network or VLAN from computers containing important personal information.
      • Keep backups of important configurations so you know what the equipment should look like.

      The larger lesson may be the most interesting one: your router isn’t merely the door to your network. If somebody takes control of it, it can become a very good seat from which to watch everything happening inside.

      Article:
      China-Linked Hackers Hid in Cisco Routers, Stole Administrator Credentials: Report — The Epoch Times

      Archived copy:
      Archive.is copy

      73

      Phillip Beall (W5EBC)

    • Author
      Posts
    Viewing 1 post (of 1 total)
    • You must be logged in to reply to this topic.
    Log In

    Footer

    Who We Are

    Red River Valley Amateur Radio Club (RRVARC) is a licensed FCC radio operator (WB5RDD) and an affiliate of the American Radio Relay League (ARRL) – The National Association for Amateur Radio®.

    Club members – hams – are persons interested in amateur radio operations and public service. The Club and its members participate in public service events such as the Tour de Paris, Field Day and educational activities, as well as during emergency preparedness activations.

    Non-Profit Organization

    The RRVARC is a 501(c)3 tax-exempt organization.

    Where We Meet

    The Red River Valley Amateur Radio Club meets at Paris Municipal Court (2910 Clarksville St, Paris, TX 75460) usually on the 4th Saturday of each month.

    Note: Special events like Field Day and some November and December meetings are excepted.  Check the events calendar for special location, dates and time.

    Website contents and logo Copyright Red River Valley Amateur Radio Club (RRVARC). Please email the webmaster (admin@rrvarc.org) with additional content or corrections.