Fire Ant Trusted-Infrastructure Espionage

Routers, TACACS, and Linux management hosts · covert access and telemetry suppression · detection, response, and hardening
Threat
Fire Ant infrastructure intrusion activity
Type
trusted-infrastructure espionage
Severity
High
Version
v0.3 Draft · 2026-09-04
Author
slapopotamus
Confidence
High behavior confidence; medium actor-overlap assessment
STATIC REVIEW PASSED
01

Executive Summary

What happened: Sygnia reported Fire Ant activity continuing into 2026 and expanding from virtualization infrastructure into Cisco IOS XR routers, TACACS services, and Linux management hosts. The observed operations used trusted infrastructure for covert connectivity, traffic collection, command-output manipulation, credential interception, and suppression of local telemetry. This creates a target-behind-the-target risk because compromised administration paths can expose connected environments even where ordinary endpoint activity appears quiet.

Observed tradecraft: The Linux layer included Medusa-related components, custom or backdoored SSH access, packet-triggered entry, masqueraded binaries and services, and tampering with login history, authentication logs, SELinux configuration, and firewall rules. The report supplies six sample hashes and several durable path behaviors. Those indicators are retrospective anchors, not a complete actor signature, and should be corroborated with host role, provenance, memory, network, authentication, and configuration evidence.

Detection strategy: Mandiant independently documented UNC3886 using active and passive router backdoors, disabling device logging, compromising Linux systems with REPTILE/MEDUSA components, and backdooring TACACS+ to capture credentials. That research corroborates the defensive value of behavior-led router, AAA, and Linux hunts but does not establish that Fire Ant and UNC3886 are the same actor. This pack preserves that attribution boundary and uses Mandiant only as independent support for the tactics and evidence strategy.

Operational consequence: Falcon endpoint telemetry can cover known process hashes, Linux staging-path execution, suspicious children of agent-like processes, log and SELinux tampering, and exact persistence paths. It cannot by itself prove control-plane compromise on a router or TACACS credential interception. Defenders need access-separated AAA, flow, configuration, and log collection; protected management paths; trusted image and configuration baselines; and memory-aware incident response. Never accept the absence of local device logs as proof that no activity occurred.

Defender priority: Treat routers, TACACS, hypervisors, and management hosts as one trust domain; preserve independent evidence and replace privileged access before eradication.
PriorityWhy nowCoverage deliveredKey limitation
Treat routers, TACACS, hypervisors, and management hosts as one trust domain; preserve independent evidence and replace privileged access before eradication.High privileged-infrastructure exposure with current technical reporting5 analyst-led CQL queries; 2 explicit telemetry gapsStatic review only; router/routing, update, AAA, or authentication semantics require non-portable telemetry
02

Source and Claim Review

Current-run snapshots retain only sanitized plain-text evidence. Remote content was handled as untrusted data and no source-supplied command, code, or instruction was executed.

IDPublisherTierIndependenceAccessedStatus
S01Sygniaprimary-incident-response-researchsygnia2026-09-03T11:03:12Zcomplete-sanitized-excerpt
S02Mandiant / Google Threat Intelligence Groupprimary-incident-response-researchmandiant-google2026-09-03T11:03:12Zcomplete-sanitized-excerpt
S03CISAgovernment-network-hardening-guidancecisa2026-09-03T11:03:12Zcomplete-sanitized-excerpt
S04Ciscovendor-configuration-guidancecisco2026-09-03T11:03:12Zcomplete-sanitized-excerpt

Claim ledger

ClaimStatementSourcesConfidenceCaveat
C01Sygnia observed Fire Ant active into 2026 and expanding into Cisco IOS XR routers, TACACS infrastructure, and Linux management hosts.S01highnone
C02Compromised routers were used for covert connectivity, traffic collection, command-output manipulation, and suppression of logging.S01highincident-specific router telemetry is not publicly reproducible
C03Sygnia observed TACACS infrastructure used to intercept authentication flows and collect credentials.S01highnone
C04Linux management hosts carried layered access including Medusa-related components, custom SSH backdoors, packet-triggered access, and masqueraded binaries.S01highnone
C05The actor tampered with Linux logs, login-history artifacts, SELinux configuration, and firewall rules.S01highnone
C06The report recommends correlating memory, disk, network, authentication, and configuration evidence because individual telemetry sources may be manipulated.S01highnone
C07Fire Ant used the compromised environment to explore reachability into connected high-value networks, creating target-behind-the-target risk.S01mediumstrategic intent is an assessment, not directly observable in every environment
C08Sygnia assesses strong behavioral overlap with public UNC3886 reporting while preserving differences in filenames, paths, and deployment details.S01mediumoverlap does not establish actor identity
C09Mandiant independently observed UNC3886 deploying custom active and passive router backdoors and disabling logging on Juniper devices.S02highdifferent vendor platform and tracking label
C10Mandiant independently observed UNC3886 targeting network and edge devices that often lack EDR coverage for long-term persistence.S02highnone
C11Mandiant observed Linux REPTILE/MEDUSA activity, custom SSH access, and a backdoored TACACS+ daemon used to capture credentials.S02highreported in UNC3886 cases, not automatically attributable to every Fire Ant incident
C12The Sygnia and Mandiant reports independently support behavior-level hunting for credential capture, covert router access, persistence, and telemetry suppression.S01, S02highactor equivalence is intentionally not claimed
C13CISA network guidance supports protected management planes, centralized authentication/logging, configuration baselines, and change monitoring.S03highgeneral authority, not campaign evidence
C14Cisco guidance documents TACACS+ authentication, authorization, and accounting controls used to establish expected administrative behavior.S04highgeneral authority, not campaign evidence
03

Hunt Brief and Attack Chain

Hypotheses are separated into endpoint hunts and explicit evidence gaps; attribution beyond the cited sources is not inferred.

StepClaimsBehaviorPlatformGoal
1C01, C07Fire Ant compromised infrastructure controlling routing, authentication, and access to connected environmentsnetwork and management infrastructurescope trust relationships and management-plane exposure
2C02routers became covert connectivity and traffic-collection platforms while suppressing evidenceCisco IOS XR routercompare configuration, runtime, AAA, flow, and independent collector evidence
3C03, C11TACACS authentication was intercepted to capture credentialsTACACS serverfind process injection, credential artifacts, and accounting gaps
4C04Linux management hosts received layered backdoors, rootkits, packet-triggered access, and masqueraded implantsLinux management hostdetect known hashes, unusual paths, service ancestry, and network activity
5C05, C06the actor altered logs, login history, SELinux, firewall rules, and command outputcross-platform infrastructureidentify tampering and validate evidence across independent sources

Hypotheses

IDBehaviorTelemetryUseLookbackValidation
H01known sample hash executionProcessRollup2hunt180d — low-volume exact hashes support retrospective scopingUse sanitized synthetic events containing the published hashes; never execute or retrieve the samples.
H02unusual Linux staging-path executionProcessRollup2hunt30d — captures active staging while limiting baseline volumeBaseline owner-approved maintenance on Linux management hosts, then validate against an inert executable copied to a lab /var/tmp path.
H03security-agent masquerading with suspicious childrenProcessRollup2hunt30d — supports baseline and incident reviewCollect 30 days of known-good agent child processes, then replay an inert shell child from a lab-named test parent; require owner exclusions.
H04Linux log and policy tampering commandsProcessRollup2hunt30d — covers likely active-response and persistence changesIn an isolated lab, run read-only utmpdump and an inert sed command against a temporary fixture, then baseline legitimate configuration-management patterns.
H05masqueraded service/startup executionProcessRollup2hunt90d — service persistence may be infrequentUse synthetic records or inert text-only fixtures; do not create system services or execute source artifacts.
H06router control-plane abuse and telemetry suppressionrouter, AAA, NetFlow, and external collector repositoriesgap30d plus configuration baselineValidate a known approved tunnel and controlled configuration change against independent collectors before defining detection logic.
H07TACACS process injection and credential captureTACACS host forensic and authentication repositoriesgap90d — long-lived infrastructure compromiseAcquire a known-good tac_plus baseline, verify library maps and accounting under a controlled administrative session, then compare forensic evidence.

Affected surface and telemetry

Surface: Cisco IOS XR routers, TACACS servers, Linux management hosts, hypervisors, and trusted administrative paths. Exposure: routing, credential authentication, administrative reachability, telemetry integrity, and connected high-value environments. Endpoint events cover only the documented process and IPv4 network views; the remaining platform evidence requires the named routing, product, authentication, AAA, configuration, or forensic repositories.

Coverage boundaries

  • IOS XR router control-plane behavior requires vendor/device and independent collector telemetry; Falcon endpoint CQL cannot cover it directly.
  • TACACS process injection and memory evidence require host forensics or documented Linux telemetry not assumed portable.
  • Deleted-but-running processes and packet-triggered backdoors require memory/process-state acquisition beyond static CQL.
  • Local logs may be attacker-manipulated; every high-confidence conclusion needs independent evidence.
  • Actor-label overlap is not a detection condition and is not used to broaden IOC attribution.
04

Consolidated IOC Table

Atomic values are transcribed only from current-run hashed source snapshots. Exact matches are retrospective evidence, not proof of maliciousness or authorization to block.

IDTypeValueContextSourcesConfidenceAction
I01sha256110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3Sygnia BridgeAgent sample hashS01highdetect
I02sha256251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0fSygnia systemd-unit-associated sample metadata hashS01highdetect
I03sha113f0c2a598e3aa63856c032a96b110aed963f0e8VMCI/VSOCK backdoor at /var/tmp/auditS01highdetect
I04sha15ba1242050b5b447052b210788a5a25593d6987dREPTILE-like binary at /var/tmp/pingS01highdetect
I05sha1be6b27f429324a4af05a310d8ec9635e37c68a94IOS XR implant at /usr/bin/acpidS01highdetect
I06sha16ef7d2985edf743ebff413a9298a127e9475d72fmasqueraded startup script at /etc/rc.d/init.d/grub-rommonS01highdetect
05

ATT&CK Mapping

ATT&CK mappings are analyst inferences from source-backed behavior, not vendor attribution statements.

TacticTechniqueNameBehaviorBasisSourcesClaims
Command and ControlT1090Proxycompromised routers and infrastructure provide covert connectivity and pivot pathsanalyst inferenceS01, S02C02, C09
Credential AccessT1557Adversary-in-the-MiddleTACACS authentication flows are intercepted to collect credentialsanalyst inferenceS01, S02C03, C11
PersistenceT1098.004Account Manipulation: SSH Authorized Keyscustom or backdoored SSH access preserves privileged entryanalyst inferenceS01, S02C04, C11
PersistenceT1543.002System Services: Systemd Servicemasqueraded services launch long-lived Linux implantsanalyst inferenceS01C04
Defense EvasionT1070.002Clear Linux or Mac System Logslogging and login-history artifacts are selectively removed or alteredanalyst inferenceS01, S02C05, C09
Defense EvasionT1036Masqueradingmalware imitates legitimate daemons and security agentsanalyst inferenceS01C04
06

Native / Non-CQL Hunts

These non-CQL hunts close the most important evidence gaps and should be correlated with the endpoint results.

HuntLog sourceLogicResponse
Router control-plane integrityIOS XR configuration/runtime, flow, PCAP, AAA, and independent collectorCompare running state with approved configuration; investigate GRE/covert paths, unexpected packet capture, output manipulation, and logging changes.Acquire volatile and configuration evidence before reload; coordinate vendor-supported recovery.
TACACS integrity and accountingtac_plus memory, binary/library maps, AAA accounting, device command logsReconcile administrator sessions and commands; compare tac_plus and loaded components to trusted digests; identify missing or contradictory records.Replace infrastructure credentials only after alternate administration is tested and evidence is preserved.
Linux management-host forensicsFalcon, memory, disk, auth logs, services, keys, firewall, SELinuxCorrelate Q01–Q05 with service/key changes, /var/tmp and /usr/lib/locate artifacts, login-history gaps, and policy changes.Segment through verified redundant paths and reimage when privileged integrity cannot be established.
07

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Query strategy: Q04 is the strongest behavior candidate; Q01 and Q05 are high-confidence known-indicator pivots. Q02-Q03 depend on infrastructure host scoping and approved maintenance baselines. Router and TACACS memory/control-plane behavior remain explicit gaps.

All queries are STATIC-ONLY. Validate event population, fields, semantics, and volume in the intended repository before operational use.

Q01 · Known Fire Ant sample hashes
CONF highFP lowCOST low

Looks for: process executions matching six source-published Fire Ant SHA1 or SHA256 values. Accomplishes: supplies a high-confidence retrospective anchor for known samples while making no claim that unchanged hashes cover the actor's full toolset.

Trace: H01 · A01

// HUNT: Fire Ant source-published process hashes on Falcon-visible Linux hosts
// HYPOTHESIS: H01
// USE: hunt
// MITRE: T1036
// CONF: high
// FP: low
// COST: low
// TIMEFRAME: 180d — exact hashes support long retrospective scoping at low expected volume
// REQUIRES: ProcessRollup2 with SHA1HashData, SHA256HashData, ImageFileName, CommandLine
// FALSE POSITIVES: approved malware-analysis fixtures or retained forensic samples in isolated lab systems
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| test(@timestamp >= now() - 15552000000)
| (SHA256HashData = "110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3" or SHA256HashData = "251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f" or SHA1HashData = "13f0c2a598e3aa63856c032a96b110aed963f0e8" or SHA1HashData = "5ba1242050b5b447052b210788a5a25593d6987d" or SHA1HashData = "be6b27f429324a4af05a310d8ec9635e37c68a94" or SHA1HashData = "6ef7d2985edf743ebff413a9298a127e9475d72f")
| table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine, SHA1HashData, SHA256HashData])
| sort(@timestamp, order=desc, limit=1000)
Q02 · Linux staging-path execution
CONF mediumFP highCOST medium

Looks for: execution from /var/tmp or /usr/lib/locate involving reported implant names or transfer and shell utilities. Accomplishes: catches the actor's Linux staging layer using path behavior that can outlast individual hashes, with administrator activity as the main noise source.

Trace: H02 · A02

// HUNT: Suspicious execution from Fire Ant Linux staging and working paths
// HYPOTHESIS: H02
// USE: hunt
// MITRE: T1105
// CONF: medium
// FP: high
// COST: medium
// TIMEFRAME: 30d — balances active staging visibility with manageable Linux baseline volume
// REQUIRES: ProcessRollup2 with ImageFileName, FileName, CommandLine, ParentBaseFileName, UserName
// FALSE POSITIVES: administrators, installers, security tools, and temporary software deployment from /var/tmp
// TUNING: scope to infrastructure-management host groups and exclude signed/hashed owner-approved maintenance binaries and change windows
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| test(@timestamp >= now() - 2592000000)
| ImageFileName = /\/(?:var\/tmp|usr\/lib\/locate)\//i
| (FileName = /^(?:audit|ping|sync|client|se\.py|u6\.py|sh|bash|scp|curl|wget)$/i or CommandLine = /(?:reverse|tunnel|pcap|tacacs|ssh)/i)
| table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine, SHA256HashData])
| sort(@timestamp, order=desc, limit=1000)
Q03 · Agent-like parent spawning utilities
CONF mediumFP highCOST medium

Looks for: shell, Python, transfer, or network utilities whose parent or grandparent resembles security agents or the reported daemon names. Accomplishes: detects masqueraded infrastructure implants through anomalous child behavior rather than relying on a mutable filename alone.

Trace: H03 · A03

// HUNT: Security-agent or daemon-like process spawning suspicious Linux utilities
// HYPOTHESIS: H03
// USE: hunt
// MITRE: T1036.005
// CONF: medium
// FP: high
// COST: medium
// TIMEFRAME: 30d — supports a representative approved-agent child-process baseline
// REQUIRES: ProcessRollup2 with ParentBaseFileName, GrandparentBaseFileName, FileName, ImageFileName, CommandLine
// FALSE POSITIVES: legitimate response actions, agent upgrades, support scripts, and monitoring plugins
// TUNING: allowlist exact approved agent child hashes and command lines after product-owner review; never exclude by parent name alone
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| test(@timestamp >= now() - 2592000000)
| FileName = /^(?:sh|bash|dash|python|python3|scp|sftp|curl|wget|nc|socat|iptables)$/i
| (ParentBaseFileName = /^(?:cybereason-agent|sentinel-agent|zabbix_agent|acpid|cupsdd|smartdd)$/i or GrandparentBaseFileName = /^(?:cybereason-agent|sentinel-agent|zabbix_agent|acpid|cupsdd|smartdd)$/i)
| table([@timestamp, ComputerName, UserName, ParentBaseFileName, GrandparentBaseFileName, FileName, ImageFileName, CommandLine])
| sort(@timestamp, order=desc, limit=1000)
Q04 · Linux log and SELinux tampering
CONF highFP mediumCOST low

Looks for: utmpdump or sed commands targeting login history, authentication logs, or SELinux configuration. Accomplishes: catches deliberate evidence and policy manipulation at execution time; it is the strongest behavior keeper but still requires benign baselining.

Trace: H04 · A04

// HUNT: Linux login-history, authentication-log, or SELinux tampering commands
// HYPOTHESIS: H04
// USE: hunt
// MITRE: T1070.002
// CONF: high
// FP: medium
// COST: low
// TIMEFRAME: 30d — captures long-lived infrastructure changes and response-period tampering
// REQUIRES: ProcessRollup2 with FileName, CommandLine, UserName, ParentBaseFileName
// FALSE POSITIVES: authorized forensic repair, configuration management, compliance testing, and administrator troubleshooting
// TUNING: exclude only ticketed automation identities and exact reviewed command patterns; retain interactive root activity
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| test(@timestamp >= now() - 2592000000)
| FileName = /^(?:utmpdump|sed)$/i
| CommandLine = /(?:\/var\/log\/(?:wtmp|utmp|btmp|secure|messages)|\/etc\/selinux\/config|\/sudo\/d)/i
| table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine])
| sort(@timestamp, order=desc, limit=1000)
Q05 · Masqueraded startup and implant paths
CONF highFP mediumCOST low

Looks for: process paths or command lines containing the reported grub-rommon, audit, ping, or tacacs.pcap artifacts. Accomplishes: finds persistence and staging with exact path pivots that complement the hash query, while remaining safe for synthetic validation.

Trace: H05 · A05

// HUNT: Fire Ant masqueraded startup and Linux implant path indicators
// HYPOTHESIS: H05
// USE: hunt
// MITRE: T1543.002
// CONF: high
// FP: medium
// COST: low
// TIMEFRAME: 90d — infrequent persistence execution warrants a longer retrospective window
// REQUIRES: ProcessRollup2 with ImageFileName, CommandLine, ParentBaseFileName, SHA1HashData
// FALSE POSITIVES: incident-response searches, copied indicator strings in scripts, or isolated lab validation
// TUNING: exclude approved forensic workstations and require host-role plus hash, service, or network corroboration
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| test(@timestamp >= now() - 7776000000)
| (ImageFileName = /\/etc\/rc\.d\/init\.d\/grub-rommon$|\/var\/tmp\/(?:audit|ping)$/i or CommandLine = /\/var\/tmp\/tacacs\.pcap|\/etc\/rc\.d\/init\.d\/grub-rommon/i)
| table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine, SHA1HashData])
| sort(@timestamp, order=desc, limit=1000)
08

Operationalization and IOA Candidates

Every query remains hunt-only. No alert package or Custom IOA is produced without tenant parse evidence, positive and benign tests, a measured baseline, routing, ownership, SLA, and rollback.

AlertQueryUseDecisionReadinessRationale
A01Q01hunthunt-onlydesign-onlyStatic-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence.
A02Q02hunthunt-onlydesign-onlyStatic-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence.
A03Q03hunthunt-onlydesign-onlyStatic-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence.
A04Q04hunthunt-onlydesign-onlyStatic-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence.
A05Q05hunthunt-onlydesign-onlyStatic-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence.
09

Machine-Readable IOC Appendix

Review expiration, infrastructure reuse, laboratory handling, and local authorization before operational use. Do not contact published infrastructure.

SHA2562 values
110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3
251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f
SHA14 values
13f0c2a598e3aa63856c032a96b110aed963f0e8
5ba1242050b5b447052b210788a5a25593d6987d
be6b27f429324a4af05a310d8ec9635e37c68a94
6ef7d2985edf743ebff413a9298a127e9475d72f
Source-tagged IOC CSV6 rows
type,value,action,severity,expiration,description,tags
sha256,110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3,detect,high,review-2026-10-03,Sygnia BridgeAgent sample hash,source:S01
sha256,251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f,detect,high,review-2026-10-03,Sygnia systemd-unit-associated sample metadata hash,source:S01
sha1,13f0c2a598e3aa63856c032a96b110aed963f0e8,detect,high,review-2026-10-03,VMCI/VSOCK backdoor at /var/tmp/audit,source:S01
sha1,5ba1242050b5b447052b210788a5a25593d6987d,detect,high,review-2026-10-03,REPTILE-like binary at /var/tmp/ping,source:S01
sha1,be6b27f429324a4af05a310d8ec9635e37c68a94,detect,high,review-2026-10-03,IOS XR implant at /usr/bin/acpid,source:S01
sha1,6ef7d2985edf743ebff413a9298a127e9475d72f,detect,high,review-2026-10-03,masqueraded startup script at /etc/rc.d/init.d/grub-rommon,source:S01
10

Hardening — Tiered and Deployable

Immediate — constrain active privileged exposure
  • Restrict infrastructure administration to dedicated paths (CTRL01) — Allow management access only from dedicated bastions and administration networks; remove direct user-segment and internet reachability; require named administrator identities and record exceptions. deployable-design Verify: From approved and unapproved test points, perform read-only reachability checks and review AAA/accounting records. Expected: Approved paths succeed with named identities; unapproved paths fail and create reviewable logs. Rollback: Restore the previous reviewed rule for the affected segment only, time-box it, and retain the exception evidence. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
  • Export independent configuration, flow, and accounting evidence (CTRL02) — Send AAA accounting, configuration changes, system logs, and flow telemetry to an access-separated collector; take signed or hashed configuration snapshots and alert when runtime state diverges from approved configuration. deployable-design Verify: Make one approved configuration change and administrative session; compare device-local, AAA, collector, and backup records. Expected: All sources agree on identity, command, time, and configuration delta; missing evidence raises an alert. Rollback: Disable only the new alert rule if noisy; retain independent collection and restore the prior retention/profile after review. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
Near-term — restore identity and host integrity
  • Harden TACACS administration and reconcile accounting (CTRL03) — Separate authentication, authorization, and command accounting; restrict TACACS server administration; baseline tac_plus executable and loaded libraries; reconcile device commands with login/session and accounting records. deployable-design Verify: Run a controlled read-only administrative session and compare device, TACACS, process/library, and collector evidence. Expected: Every command has a named session and matching accounting record; tac_plus binary/library baseline is unchanged. Rollback: Restore the prior documented AAA policy for the pilot device/server and use tested local break-glass credentials while correcting the configuration. Authority: S04 · Cisco TACACS Configuration Guide, accessed 2026-09-03.
  • Enforce host integrity and protected Linux policy (CTRL04) — Remove unapproved services and SSH keys, enforce supported SELinux policy where compatible, monitor /var/tmp and /usr/lib/locate execution, protect authentication logs, and compare critical binaries/services to known-good digests. deployable-design Verify: Run Q02-Q05 over the pilot, compare services/keys/digests, and confirm required management workflows under enforcing policy. Expected: Only approved services/keys execute; policy remains enforcing; expected workflows and telemetry remain healthy. Rollback: Restore the previous reviewed SELinux policy or service configuration for the pilot, keep the host segmented, and remediate compatibility before expansion. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
Strategic — remove the recurring trust failure
  • Use independent evidence paths for high-trust infrastructure (CTRL05) — Maintain at least two independent evidence paths for administrative sessions and configuration state, such as device/AAA accounting plus access-separated flow/configuration collection; test evidence availability quarterly. deployable-design Verify: Conduct a table-top plus controlled admin/configuration event and retrieve evidence independently from each path. Expected: Both paths reconstruct actor, action, time, target, and configuration effect; loss of either is detected. Rollback: Retain the primary collector and revert the secondary pilot after exporting evidence if the design fails separation or continuity review. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
  • Keep network devices supported and verify trusted images (CTRL06) — Replace unsupported hardware/software, obtain images only from vendor-authorized channels, verify published digests/signatures, back up reviewed configuration, and run vendor integrity tooling after upgrade. deployable-design Verify: Verify running version/image digest, configuration restore, routing health, AAA, telemetry, and vendor integrity result. Expected: Supported image and reviewed configuration operate normally with intact AAA and independent telemetry. Rollback: Boot the prior known-good supported image and restore the hashed configuration through out-of-band access if health checks fail. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.

Deployable playbook · Management-plane restriction and evidence pilot

  1. Inventory the pilot router, TACACS server, bastion, routes, administrator identities, and trusted dependencies.
  2. Capture current ACLs, management reachability, AAA/accounting, configuration digest, collector settings, and break-glass state.
  3. Apply dedicated-path access on one redundant or low-risk segment and enable access-separated configuration/flow/accounting collection.
  4. Verify approved access succeeds, unapproved access fails, and a controlled configuration change appears consistently in all evidence paths.
  5. Run service and routing health checks before expanding to another segment.
  6. Expand only when break-glass access, telemetry, and operations pass; stop on missing or contradictory evidence.
  7. Rollback the pilot ACL through out-of-band access if continuity fails; keep independent collection enabled.
  8. Retain before/after policies, configuration digests, session/accounting evidence, and approvals.

Deployable playbook · Linux management-host integrity ring

  1. Select a rebuilt or known-good Linux management host and record tac_plus, services, libraries, keys, SELinux state, and critical digests.
  2. Confirm tested break-glass access, application compatibility, EDR/log delivery, and a recovery image.
  3. Pilot protected policy, approved service/key inventory, path monitoring, and AAA reconciliation.
  4. Verify Q02-Q05, management workflows, command accounting, and expected independent logs.
  5. Expand by host role only after seven days of healthy operation and reviewed baseline results.
  6. Rollback the previous reviewed policy on the pilot if workflows fail; keep it segmented while compatibility is corrected.
  7. Retain baseline and after-state digests, query results, health checks, and change approval.
Design state: no control is canary-tested or deployed. Complete environment, dependency, continuity, and approval checks before execution.
11

Containment Runbook

PhaseTriggerAuthorityOwnerEvidenceRecovery
1 — Activate and preserveQ01/Q05 exact indicator, Q04 tampering evidence, or corroborated router/TACACS anomalyIncident commanderSOC, network forensics, and Linux forensicsRaw query results, process trees, memory, files/hashes, flow/AAA, configuration/runtime state, local and independent logsNo reboot, log cleanup, credential rotation, or device replacement until volatile evidence and continuity paths are recorded
2 — Bound the trust domainEvidence of privileged infrastructure compromise or manipulated telemetryIncident commander plus network service ownerNetwork architecture and incident responseRoutes, peers, management paths, shared AAA, bastions, hypervisors, connected organizations, session stateMaintain critical routing through verified redundant paths; stop if isolation would create unsafe outage
3 — Constrain and replace accessTrust map complete and alternate administration testedIdentity/network change controlIdentity and network platform teamsDisabled paths, reissued credentials/keys, AAA changes, active-session termination recordsUse tested local break-glass identities and out-of-band paths; restore one path only under time-boxed incident exception
4 — Reimage and restore infrastructureRoot/control-plane compromise confirmed or integrity cannot be establishedIncident commander and service ownerNetwork and Linux recovery teamsVendor image digests, configuration backups, rebuild logs, integrity and health resultsBoot prior known-good supported image/configuration on redundant equipment if validation fails
5 — Validate and closeAll access paths replaced, independent evidence reconciles, and services are stableIncident commanderDetection engineering, network, and Linux owners30-day Q01-Q05 re-hunt, AAA/config/flow reconciliation, no unexplained gaps, exception closureReopen scope and containment on any new indicator, evidence mismatch, or unauthorized trust path

Continuity rule: preserve volatile evidence and verify alternate administration before isolation, reboot, credential replacement, device reload, or host rebuild.

12

Detection Coverage and Validation Evidence

Validation state: STATIC REVIEW PASSED after local structure/safety, maintained-field, CQL heuristic, provenance, and duplicate gates. This is not Falcon parsing, canary success, or deployment evidence.

TechniqueCoverageQuery / handoffEvidenceLimitation
T1090Designnative evidence handoffSource-backed behavior and non-CQL reviewNo portable endpoint query for this behavior
T1557Designnative evidence handoffSource-backed behavior and non-CQL reviewNo portable endpoint query for this behavior
T1098.004Designnative evidence handoffSource-backed behavior and non-CQL reviewNo portable endpoint query for this behavior
T1543.002StaticQ05Local static gatesTenant parsing and baseline absent
T1070.002StaticQ04Local static gatesTenant parsing and baseline absent
T1036StaticQ01, Q03Local static gatesTenant parsing and baseline absent
Telemetry gapGapH06Documented design handoffRouter GRE, PCAP, AAA, SNMP, and runtime/configuration divergence require device and independent collector telemetry.
Telemetry gapGapH07Documented design handofftac_plus injection and credential-capture evidence requires memory, library-map, file, and AAA schema not assumed portable.

Recorded evidence

  • Every CQL card remains tenant-unverified and was not executed against Falcon.
  • The offline tenant-validation dry run checks extraction and profile readiness only; it does not contact a tenant.
  • IOC rows are bound to current hashed snapshots and require context before action.
  • Next step: run each query manually in a safe one-hour window, confirm fields and semantics, then expand to the documented lookback.
13

Hunt Summary Ticket

TITLE:        Fire Ant Trusted-Infrastructure Espionage hunt — v0.3 Draft
SEVERITY:     high — privileged infrastructure or root trust may be compromised
SCOPE:        Cisco IOS XR routers, TACACS servers, Linux management hosts, hypervisors, and trusted administrative paths; endpoint and independent infrastructure evidence
HYPOTHESIS:   H01 hunt; H02 hunt; H03 hunt; H04 hunt; H05 hunt; H06 gap; H07 gap
QUERIES RUN:  Q01 hunt; Q02 hunt; Q03 hunt; Q04 hunt; Q05 hunt; no alert-candidate query
DO FIRST:     Run Q04 over 30 days on Linux infrastructure hosts, then correlate tampering commands with independent AAA and configuration evidence.
FINDINGS:
GAPS:         IOS XR router control-plane behavior requires vendor/device and independent collector telemetry; Falcon endpoint CQL cannot cover it directly.; TACACS process injection and memory evidence require host forensics or documented Linux telemetry not assumed portable.; Deleted-but-running processes and packet-triggered backdoors require memory/process-state acquisition beyond static CQL.; Local logs may be attacker-manipulated; every high-confidence conclusion needs independent evidence.; Actor-label overlap is not a detection condition and is not used to broaden IOC attribution.
ACTIONS:      preserve evidence; validate queries; assign platform, network, identity, and recovery owners
OWNER:        Incident Response / SOC / Infrastructure Platform / Network Security
VERSION:      v0.3 Draft · 2026-09-04 · STATIC REVIEW PASSED
14

Changelog

v0.3 Rich visual emphasis2026-09-04Added coordinated semantic color to Executive Summary lead-ins, threat metadata, Severity, and IOC counts. Detection logic, evidence, indicators, hardening, and validation claims are unchanged.
v0.2 Theme refresh2026-09-04Applied the deterministic threat-aware HuntPack palette. Detection logic, evidence, indicators, hardening, and validation claims are unchanged.
v0.1 Draft2026-09-03Initial pack with 5 conservative CQL queries, 2 explicit gaps, 4 sanitized sources, 6 source-bound IOCs, 6 reversible controls, two playbooks, and a five-phase containment workflow. Tenant execution is not claimed.
15

References

IDPublisherEdition/dateAccessedUseURL
S01Sygniacurrent cited edition2026-09-03T11:03:12ZCurrent Fire Ant incident research and indicatorshttps://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
S02Mandiant / Google Threat Intelligence Groupcurrent cited edition2026-09-03T11:03:12ZIndependent behavior corroboration; no actor equivalencehttps://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers
S03CISAcurrent cited edition2026-09-03T11:03:12ZNetwork-management and evidence hardeninghttps://www.cisa.gov/resources-tools/resources/network-infrastructure-security-guide
S04Ciscocurrent cited edition2026-09-03T11:03:12ZTACACS authentication, authorization, and accounting authorityhttps://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/200467-TACACS-Configuration-Guide.html