Fire Ant Trusted-Infrastructure Espionage
Executive Summary
What happened: Sygnia reported Fire Ant activity continuing into 2026 and expanding from virtualization infrastructure into Cisco IOS XR routers, TACACS services, and Linux management hosts. The observed operations used trusted infrastructure for covert connectivity, traffic collection, command-output manipulation, credential interception, and suppression of local telemetry. This creates a target-behind-the-target risk because compromised administration paths can expose connected environments even where ordinary endpoint activity appears quiet.
Observed tradecraft: The Linux layer included Medusa-related components, custom or backdoored SSH access, packet-triggered entry, masqueraded binaries and services, and tampering with login history, authentication logs, SELinux configuration, and firewall rules. The report supplies six sample hashes and several durable path behaviors. Those indicators are retrospective anchors, not a complete actor signature, and should be corroborated with host role, provenance, memory, network, authentication, and configuration evidence.
Detection strategy: Mandiant independently documented UNC3886 using active and passive router backdoors, disabling device logging, compromising Linux systems with REPTILE/MEDUSA components, and backdooring TACACS+ to capture credentials. That research corroborates the defensive value of behavior-led router, AAA, and Linux hunts but does not establish that Fire Ant and UNC3886 are the same actor. This pack preserves that attribution boundary and uses Mandiant only as independent support for the tactics and evidence strategy.
Operational consequence: Falcon endpoint telemetry can cover known process hashes, Linux staging-path execution, suspicious children of agent-like processes, log and SELinux tampering, and exact persistence paths. It cannot by itself prove control-plane compromise on a router or TACACS credential interception. Defenders need access-separated AAA, flow, configuration, and log collection; protected management paths; trusted image and configuration baselines; and memory-aware incident response. Never accept the absence of local device logs as proof that no activity occurred.
| Priority | Why now | Coverage delivered | Key limitation |
|---|---|---|---|
| Treat routers, TACACS, hypervisors, and management hosts as one trust domain; preserve independent evidence and replace privileged access before eradication. | High privileged-infrastructure exposure with current technical reporting | 5 analyst-led CQL queries; 2 explicit telemetry gaps | Static review only; router/routing, update, AAA, or authentication semantics require non-portable telemetry |
Source and Claim Review
Current-run snapshots retain only sanitized plain-text evidence. Remote content was handled as untrusted data and no source-supplied command, code, or instruction was executed.
| ID | Publisher | Tier | Independence | Accessed | Status |
|---|---|---|---|---|---|
| S01 | Sygnia | primary-incident-response-research | sygnia | 2026-09-03T11:03:12Z | complete-sanitized-excerpt |
| S02 | Mandiant / Google Threat Intelligence Group | primary-incident-response-research | mandiant-google | 2026-09-03T11:03:12Z | complete-sanitized-excerpt |
| S03 | CISA | government-network-hardening-guidance | cisa | 2026-09-03T11:03:12Z | complete-sanitized-excerpt |
| S04 | Cisco | vendor-configuration-guidance | cisco | 2026-09-03T11:03:12Z | complete-sanitized-excerpt |
Claim ledger
| Claim | Statement | Sources | Confidence | Caveat |
|---|---|---|---|---|
| C01 | Sygnia observed Fire Ant active into 2026 and expanding into Cisco IOS XR routers, TACACS infrastructure, and Linux management hosts. | S01 | high | none |
| C02 | Compromised routers were used for covert connectivity, traffic collection, command-output manipulation, and suppression of logging. | S01 | high | incident-specific router telemetry is not publicly reproducible |
| C03 | Sygnia observed TACACS infrastructure used to intercept authentication flows and collect credentials. | S01 | high | none |
| C04 | Linux management hosts carried layered access including Medusa-related components, custom SSH backdoors, packet-triggered access, and masqueraded binaries. | S01 | high | none |
| C05 | The actor tampered with Linux logs, login-history artifacts, SELinux configuration, and firewall rules. | S01 | high | none |
| C06 | The report recommends correlating memory, disk, network, authentication, and configuration evidence because individual telemetry sources may be manipulated. | S01 | high | none |
| C07 | Fire Ant used the compromised environment to explore reachability into connected high-value networks, creating target-behind-the-target risk. | S01 | medium | strategic intent is an assessment, not directly observable in every environment |
| C08 | Sygnia assesses strong behavioral overlap with public UNC3886 reporting while preserving differences in filenames, paths, and deployment details. | S01 | medium | overlap does not establish actor identity |
| C09 | Mandiant independently observed UNC3886 deploying custom active and passive router backdoors and disabling logging on Juniper devices. | S02 | high | different vendor platform and tracking label |
| C10 | Mandiant independently observed UNC3886 targeting network and edge devices that often lack EDR coverage for long-term persistence. | S02 | high | none |
| C11 | Mandiant observed Linux REPTILE/MEDUSA activity, custom SSH access, and a backdoored TACACS+ daemon used to capture credentials. | S02 | high | reported in UNC3886 cases, not automatically attributable to every Fire Ant incident |
| C12 | The Sygnia and Mandiant reports independently support behavior-level hunting for credential capture, covert router access, persistence, and telemetry suppression. | S01, S02 | high | actor equivalence is intentionally not claimed |
| C13 | CISA network guidance supports protected management planes, centralized authentication/logging, configuration baselines, and change monitoring. | S03 | high | general authority, not campaign evidence |
| C14 | Cisco guidance documents TACACS+ authentication, authorization, and accounting controls used to establish expected administrative behavior. | S04 | high | general authority, not campaign evidence |
Hunt Brief and Attack Chain
Hypotheses are separated into endpoint hunts and explicit evidence gaps; attribution beyond the cited sources is not inferred.
| Step | Claims | Behavior | Platform | Goal |
|---|---|---|---|---|
| 1 | C01, C07 | Fire Ant compromised infrastructure controlling routing, authentication, and access to connected environments | network and management infrastructure | scope trust relationships and management-plane exposure |
| 2 | C02 | routers became covert connectivity and traffic-collection platforms while suppressing evidence | Cisco IOS XR router | compare configuration, runtime, AAA, flow, and independent collector evidence |
| 3 | C03, C11 | TACACS authentication was intercepted to capture credentials | TACACS server | find process injection, credential artifacts, and accounting gaps |
| 4 | C04 | Linux management hosts received layered backdoors, rootkits, packet-triggered access, and masqueraded implants | Linux management host | detect known hashes, unusual paths, service ancestry, and network activity |
| 5 | C05, C06 | the actor altered logs, login history, SELinux, firewall rules, and command output | cross-platform infrastructure | identify tampering and validate evidence across independent sources |
Hypotheses
| ID | Behavior | Telemetry | Use | Lookback | Validation |
|---|---|---|---|---|---|
| H01 | known sample hash execution | ProcessRollup2 | hunt | 180d — low-volume exact hashes support retrospective scoping | Use sanitized synthetic events containing the published hashes; never execute or retrieve the samples. |
| H02 | unusual Linux staging-path execution | ProcessRollup2 | hunt | 30d — captures active staging while limiting baseline volume | Baseline owner-approved maintenance on Linux management hosts, then validate against an inert executable copied to a lab /var/tmp path. |
| H03 | security-agent masquerading with suspicious children | ProcessRollup2 | hunt | 30d — supports baseline and incident review | Collect 30 days of known-good agent child processes, then replay an inert shell child from a lab-named test parent; require owner exclusions. |
| H04 | Linux log and policy tampering commands | ProcessRollup2 | hunt | 30d — covers likely active-response and persistence changes | In an isolated lab, run read-only utmpdump and an inert sed command against a temporary fixture, then baseline legitimate configuration-management patterns. |
| H05 | masqueraded service/startup execution | ProcessRollup2 | hunt | 90d — service persistence may be infrequent | Use synthetic records or inert text-only fixtures; do not create system services or execute source artifacts. |
| H06 | router control-plane abuse and telemetry suppression | router, AAA, NetFlow, and external collector repositories | gap | 30d plus configuration baseline | Validate a known approved tunnel and controlled configuration change against independent collectors before defining detection logic. |
| H07 | TACACS process injection and credential capture | TACACS host forensic and authentication repositories | gap | 90d — long-lived infrastructure compromise | Acquire a known-good tac_plus baseline, verify library maps and accounting under a controlled administrative session, then compare forensic evidence. |
Affected surface and telemetry
Surface: Cisco IOS XR routers, TACACS servers, Linux management hosts, hypervisors, and trusted administrative paths. Exposure: routing, credential authentication, administrative reachability, telemetry integrity, and connected high-value environments. Endpoint events cover only the documented process and IPv4 network views; the remaining platform evidence requires the named routing, product, authentication, AAA, configuration, or forensic repositories.
Coverage boundaries
- IOS XR router control-plane behavior requires vendor/device and independent collector telemetry; Falcon endpoint CQL cannot cover it directly.
- TACACS process injection and memory evidence require host forensics or documented Linux telemetry not assumed portable.
- Deleted-but-running processes and packet-triggered backdoors require memory/process-state acquisition beyond static CQL.
- Local logs may be attacker-manipulated; every high-confidence conclusion needs independent evidence.
- Actor-label overlap is not a detection condition and is not used to broaden IOC attribution.
Consolidated IOC Table
Atomic values are transcribed only from current-run hashed source snapshots. Exact matches are retrospective evidence, not proof of maliciousness or authorization to block.
| ID | Type | Value | Context | Sources | Confidence | Action |
|---|---|---|---|---|---|---|
| I01 | sha256 | 110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3 | Sygnia BridgeAgent sample hash | S01 | high | detect |
| I02 | sha256 | 251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f | Sygnia systemd-unit-associated sample metadata hash | S01 | high | detect |
| I03 | sha1 | 13f0c2a598e3aa63856c032a96b110aed963f0e8 | VMCI/VSOCK backdoor at /var/tmp/audit | S01 | high | detect |
| I04 | sha1 | 5ba1242050b5b447052b210788a5a25593d6987d | REPTILE-like binary at /var/tmp/ping | S01 | high | detect |
| I05 | sha1 | be6b27f429324a4af05a310d8ec9635e37c68a94 | IOS XR implant at /usr/bin/acpid | S01 | high | detect |
| I06 | sha1 | 6ef7d2985edf743ebff413a9298a127e9475d72f | masqueraded startup script at /etc/rc.d/init.d/grub-rommon | S01 | high | detect |
ATT&CK Mapping
ATT&CK mappings are analyst inferences from source-backed behavior, not vendor attribution statements.
| Tactic | Technique | Name | Behavior | Basis | Sources | Claims |
|---|---|---|---|---|---|---|
| Command and Control | T1090 | Proxy | compromised routers and infrastructure provide covert connectivity and pivot paths | analyst inference | S01, S02 | C02, C09 |
| Credential Access | T1557 | Adversary-in-the-Middle | TACACS authentication flows are intercepted to collect credentials | analyst inference | S01, S02 | C03, C11 |
| Persistence | T1098.004 | Account Manipulation: SSH Authorized Keys | custom or backdoored SSH access preserves privileged entry | analyst inference | S01, S02 | C04, C11 |
| Persistence | T1543.002 | System Services: Systemd Service | masqueraded services launch long-lived Linux implants | analyst inference | S01 | C04 |
| Defense Evasion | T1070.002 | Clear Linux or Mac System Logs | logging and login-history artifacts are selectively removed or altered | analyst inference | S01, S02 | C05, C09 |
| Defense Evasion | T1036 | Masquerading | malware imitates legitimate daemons and security agents | analyst inference | S01 | C04 |
Native / Non-CQL Hunts
These non-CQL hunts close the most important evidence gaps and should be correlated with the endpoint results.
| Hunt | Log source | Logic | Response |
|---|---|---|---|
| Router control-plane integrity | IOS XR configuration/runtime, flow, PCAP, AAA, and independent collector | Compare running state with approved configuration; investigate GRE/covert paths, unexpected packet capture, output manipulation, and logging changes. | Acquire volatile and configuration evidence before reload; coordinate vendor-supported recovery. |
| TACACS integrity and accounting | tac_plus memory, binary/library maps, AAA accounting, device command logs | Reconcile administrator sessions and commands; compare tac_plus and loaded components to trusted digests; identify missing or contradictory records. | Replace infrastructure credentials only after alternate administration is tested and evidence is preserved. |
| Linux management-host forensics | Falcon, memory, disk, auth logs, services, keys, firewall, SELinux | Correlate Q01–Q05 with service/key changes, /var/tmp and /usr/lib/locate artifacts, login-history gaps, and policy changes. | Segment through verified redundant paths and reimage when privileged integrity cannot be established. |
CrowdStrike LogScale CQL Hunt Queries
All queries are STATIC-ONLY. Validate event population, fields, semantics, and volume in the intended repository before operational use.
Looks for: process executions matching six source-published Fire Ant SHA1 or SHA256 values. Accomplishes: supplies a high-confidence retrospective anchor for known samples while making no claim that unchanged hashes cover the actor's full toolset.
// HUNT: Fire Ant source-published process hashes on Falcon-visible Linux hosts // HYPOTHESIS: H01 // USE: hunt // MITRE: T1036 // CONF: high // FP: low // COST: low // TIMEFRAME: 180d — exact hashes support long retrospective scoping at low expected volume // REQUIRES: ProcessRollup2 with SHA1HashData, SHA256HashData, ImageFileName, CommandLine // FALSE POSITIVES: approved malware-analysis fixtures or retained forensic samples in isolated lab systems // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | test(@timestamp >= now() - 15552000000) | (SHA256HashData = "110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3" or SHA256HashData = "251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f" or SHA1HashData = "13f0c2a598e3aa63856c032a96b110aed963f0e8" or SHA1HashData = "5ba1242050b5b447052b210788a5a25593d6987d" or SHA1HashData = "be6b27f429324a4af05a310d8ec9635e37c68a94" or SHA1HashData = "6ef7d2985edf743ebff413a9298a127e9475d72f") | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine, SHA1HashData, SHA256HashData]) | sort(@timestamp, order=desc, limit=1000)
Looks for: execution from /var/tmp or /usr/lib/locate involving reported implant names or transfer and shell utilities. Accomplishes: catches the actor's Linux staging layer using path behavior that can outlast individual hashes, with administrator activity as the main noise source.
// HUNT: Suspicious execution from Fire Ant Linux staging and working paths // HYPOTHESIS: H02 // USE: hunt // MITRE: T1105 // CONF: medium // FP: high // COST: medium // TIMEFRAME: 30d — balances active staging visibility with manageable Linux baseline volume // REQUIRES: ProcessRollup2 with ImageFileName, FileName, CommandLine, ParentBaseFileName, UserName // FALSE POSITIVES: administrators, installers, security tools, and temporary software deployment from /var/tmp // TUNING: scope to infrastructure-management host groups and exclude signed/hashed owner-approved maintenance binaries and change windows // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | test(@timestamp >= now() - 2592000000) | ImageFileName = /\/(?:var\/tmp|usr\/lib\/locate)\//i | (FileName = /^(?:audit|ping|sync|client|se\.py|u6\.py|sh|bash|scp|curl|wget)$/i or CommandLine = /(?:reverse|tunnel|pcap|tacacs|ssh)/i) | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine, SHA256HashData]) | sort(@timestamp, order=desc, limit=1000)
Looks for: shell, Python, transfer, or network utilities whose parent or grandparent resembles security agents or the reported daemon names. Accomplishes: detects masqueraded infrastructure implants through anomalous child behavior rather than relying on a mutable filename alone.
// HUNT: Security-agent or daemon-like process spawning suspicious Linux utilities // HYPOTHESIS: H03 // USE: hunt // MITRE: T1036.005 // CONF: medium // FP: high // COST: medium // TIMEFRAME: 30d — supports a representative approved-agent child-process baseline // REQUIRES: ProcessRollup2 with ParentBaseFileName, GrandparentBaseFileName, FileName, ImageFileName, CommandLine // FALSE POSITIVES: legitimate response actions, agent upgrades, support scripts, and monitoring plugins // TUNING: allowlist exact approved agent child hashes and command lines after product-owner review; never exclude by parent name alone // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | test(@timestamp >= now() - 2592000000) | FileName = /^(?:sh|bash|dash|python|python3|scp|sftp|curl|wget|nc|socat|iptables)$/i | (ParentBaseFileName = /^(?:cybereason-agent|sentinel-agent|zabbix_agent|acpid|cupsdd|smartdd)$/i or GrandparentBaseFileName = /^(?:cybereason-agent|sentinel-agent|zabbix_agent|acpid|cupsdd|smartdd)$/i) | table([@timestamp, ComputerName, UserName, ParentBaseFileName, GrandparentBaseFileName, FileName, ImageFileName, CommandLine]) | sort(@timestamp, order=desc, limit=1000)
Looks for: utmpdump or sed commands targeting login history, authentication logs, or SELinux configuration. Accomplishes: catches deliberate evidence and policy manipulation at execution time; it is the strongest behavior keeper but still requires benign baselining.
// HUNT: Linux login-history, authentication-log, or SELinux tampering commands // HYPOTHESIS: H04 // USE: hunt // MITRE: T1070.002 // CONF: high // FP: medium // COST: low // TIMEFRAME: 30d — captures long-lived infrastructure changes and response-period tampering // REQUIRES: ProcessRollup2 with FileName, CommandLine, UserName, ParentBaseFileName // FALSE POSITIVES: authorized forensic repair, configuration management, compliance testing, and administrator troubleshooting // TUNING: exclude only ticketed automation identities and exact reviewed command patterns; retain interactive root activity // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | test(@timestamp >= now() - 2592000000) | FileName = /^(?:utmpdump|sed)$/i | CommandLine = /(?:\/var\/log\/(?:wtmp|utmp|btmp|secure|messages)|\/etc\/selinux\/config|\/sudo\/d)/i | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine]) | sort(@timestamp, order=desc, limit=1000)
Looks for: process paths or command lines containing the reported grub-rommon, audit, ping, or tacacs.pcap artifacts. Accomplishes: finds persistence and staging with exact path pivots that complement the hash query, while remaining safe for synthetic validation.
// HUNT: Fire Ant masqueraded startup and Linux implant path indicators // HYPOTHESIS: H05 // USE: hunt // MITRE: T1543.002 // CONF: high // FP: medium // COST: low // TIMEFRAME: 90d — infrequent persistence execution warrants a longer retrospective window // REQUIRES: ProcessRollup2 with ImageFileName, CommandLine, ParentBaseFileName, SHA1HashData // FALSE POSITIVES: incident-response searches, copied indicator strings in scripts, or isolated lab validation // TUNING: exclude approved forensic workstations and require host-role plus hash, service, or network corroboration // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | test(@timestamp >= now() - 7776000000) | (ImageFileName = /\/etc\/rc\.d\/init\.d\/grub-rommon$|\/var\/tmp\/(?:audit|ping)$/i or CommandLine = /\/var\/tmp\/tacacs\.pcap|\/etc\/rc\.d\/init\.d\/grub-rommon/i) | table([@timestamp, ComputerName, UserName, ParentBaseFileName, FileName, ImageFileName, CommandLine, SHA1HashData]) | sort(@timestamp, order=desc, limit=1000)
Operationalization and IOA Candidates
Every query remains hunt-only. No alert package or Custom IOA is produced without tenant parse evidence, positive and benign tests, a measured baseline, routing, ownership, SLA, and rollback.
| Alert | Query | Use | Decision | Readiness | Rationale |
|---|---|---|---|---|---|
| A01 | Q01 | hunt | hunt-only | design-only | Static-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence. |
| A02 | Q02 | hunt | hunt-only | design-only | Static-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence. |
| A03 | Q03 | hunt | hunt-only | design-only | Static-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence. |
| A04 | Q04 | hunt | hunt-only | design-only | Static-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence. |
| A05 | Q05 | hunt | hunt-only | design-only | Static-only query with no tenant parse, measured benign baseline, positive test, cadence, suppression, route, owner, or SLA evidence. |
Machine-Readable IOC Appendix
Review expiration, infrastructure reuse, laboratory handling, and local authorization before operational use. Do not contact published infrastructure.
110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3 251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f
13f0c2a598e3aa63856c032a96b110aed963f0e8 5ba1242050b5b447052b210788a5a25593d6987d be6b27f429324a4af05a310d8ec9635e37c68a94 6ef7d2985edf743ebff413a9298a127e9475d72f
type,value,action,severity,expiration,description,tags sha256,110e6fb23be00d2ed251a445ee5b65aadf23b48b8db7419900d64539ad90c5a3,detect,high,review-2026-10-03,Sygnia BridgeAgent sample hash,source:S01 sha256,251c7a2684542c29ae2c1e1282b780163bf9f844179ef0759094b2b7e2f62f0f,detect,high,review-2026-10-03,Sygnia systemd-unit-associated sample metadata hash,source:S01 sha1,13f0c2a598e3aa63856c032a96b110aed963f0e8,detect,high,review-2026-10-03,VMCI/VSOCK backdoor at /var/tmp/audit,source:S01 sha1,5ba1242050b5b447052b210788a5a25593d6987d,detect,high,review-2026-10-03,REPTILE-like binary at /var/tmp/ping,source:S01 sha1,be6b27f429324a4af05a310d8ec9635e37c68a94,detect,high,review-2026-10-03,IOS XR implant at /usr/bin/acpid,source:S01 sha1,6ef7d2985edf743ebff413a9298a127e9475d72f,detect,high,review-2026-10-03,masqueraded startup script at /etc/rc.d/init.d/grub-rommon,source:S01
Hardening — Tiered and Deployable
- Restrict infrastructure administration to dedicated paths (CTRL01) — Allow management access only from dedicated bastions and administration networks; remove direct user-segment and internet reachability; require named administrator identities and record exceptions. deployable-design Verify: From approved and unapproved test points, perform read-only reachability checks and review AAA/accounting records. Expected: Approved paths succeed with named identities; unapproved paths fail and create reviewable logs. Rollback: Restore the previous reviewed rule for the affected segment only, time-box it, and retain the exception evidence. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
- Export independent configuration, flow, and accounting evidence (CTRL02) — Send AAA accounting, configuration changes, system logs, and flow telemetry to an access-separated collector; take signed or hashed configuration snapshots and alert when runtime state diverges from approved configuration. deployable-design Verify: Make one approved configuration change and administrative session; compare device-local, AAA, collector, and backup records. Expected: All sources agree on identity, command, time, and configuration delta; missing evidence raises an alert. Rollback: Disable only the new alert rule if noisy; retain independent collection and restore the prior retention/profile after review. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
- Harden TACACS administration and reconcile accounting (CTRL03) — Separate authentication, authorization, and command accounting; restrict TACACS server administration; baseline tac_plus executable and loaded libraries; reconcile device commands with login/session and accounting records. deployable-design Verify: Run a controlled read-only administrative session and compare device, TACACS, process/library, and collector evidence. Expected: Every command has a named session and matching accounting record; tac_plus binary/library baseline is unchanged. Rollback: Restore the prior documented AAA policy for the pilot device/server and use tested local break-glass credentials while correcting the configuration. Authority: S04 · Cisco TACACS Configuration Guide, accessed 2026-09-03.
- Enforce host integrity and protected Linux policy (CTRL04) — Remove unapproved services and SSH keys, enforce supported SELinux policy where compatible, monitor /var/tmp and /usr/lib/locate execution, protect authentication logs, and compare critical binaries/services to known-good digests. deployable-design Verify: Run Q02-Q05 over the pilot, compare services/keys/digests, and confirm required management workflows under enforcing policy. Expected: Only approved services/keys execute; policy remains enforcing; expected workflows and telemetry remain healthy. Rollback: Restore the previous reviewed SELinux policy or service configuration for the pilot, keep the host segmented, and remediate compatibility before expansion. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
- Use independent evidence paths for high-trust infrastructure (CTRL05) — Maintain at least two independent evidence paths for administrative sessions and configuration state, such as device/AAA accounting plus access-separated flow/configuration collection; test evidence availability quarterly. deployable-design Verify: Conduct a table-top plus controlled admin/configuration event and retrieve evidence independently from each path. Expected: Both paths reconstruct actor, action, time, target, and configuration effect; loss of either is detected. Rollback: Retain the primary collector and revert the secondary pilot after exporting evidence if the design fails separation or continuity review. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
- Keep network devices supported and verify trusted images (CTRL06) — Replace unsupported hardware/software, obtain images only from vendor-authorized channels, verify published digests/signatures, back up reviewed configuration, and run vendor integrity tooling after upgrade. deployable-design Verify: Verify running version/image digest, configuration restore, routing health, AAA, telemetry, and vendor integrity result. Expected: Supported image and reviewed configuration operate normally with intact AAA and independent telemetry. Rollback: Boot the prior known-good supported image and restore the hashed configuration through out-of-band access if health checks fail. Authority: S03 · CISA Network Infrastructure Security Guide, accessed 2026-09-03.
Deployable playbook · Management-plane restriction and evidence pilot
- Inventory the pilot router, TACACS server, bastion, routes, administrator identities, and trusted dependencies.
- Capture current ACLs, management reachability, AAA/accounting, configuration digest, collector settings, and break-glass state.
- Apply dedicated-path access on one redundant or low-risk segment and enable access-separated configuration/flow/accounting collection.
- Verify approved access succeeds, unapproved access fails, and a controlled configuration change appears consistently in all evidence paths.
- Run service and routing health checks before expanding to another segment.
- Expand only when break-glass access, telemetry, and operations pass; stop on missing or contradictory evidence.
- Rollback the pilot ACL through out-of-band access if continuity fails; keep independent collection enabled.
- Retain before/after policies, configuration digests, session/accounting evidence, and approvals.
Deployable playbook · Linux management-host integrity ring
- Select a rebuilt or known-good Linux management host and record tac_plus, services, libraries, keys, SELinux state, and critical digests.
- Confirm tested break-glass access, application compatibility, EDR/log delivery, and a recovery image.
- Pilot protected policy, approved service/key inventory, path monitoring, and AAA reconciliation.
- Verify Q02-Q05, management workflows, command accounting, and expected independent logs.
- Expand by host role only after seven days of healthy operation and reviewed baseline results.
- Rollback the previous reviewed policy on the pilot if workflows fail; keep it segmented while compatibility is corrected.
- Retain baseline and after-state digests, query results, health checks, and change approval.
Containment Runbook
| Phase | Trigger | Authority | Owner | Evidence | Recovery |
|---|---|---|---|---|---|
| 1 — Activate and preserve | Q01/Q05 exact indicator, Q04 tampering evidence, or corroborated router/TACACS anomaly | Incident commander | SOC, network forensics, and Linux forensics | Raw query results, process trees, memory, files/hashes, flow/AAA, configuration/runtime state, local and independent logs | No reboot, log cleanup, credential rotation, or device replacement until volatile evidence and continuity paths are recorded |
| 2 — Bound the trust domain | Evidence of privileged infrastructure compromise or manipulated telemetry | Incident commander plus network service owner | Network architecture and incident response | Routes, peers, management paths, shared AAA, bastions, hypervisors, connected organizations, session state | Maintain critical routing through verified redundant paths; stop if isolation would create unsafe outage |
| 3 — Constrain and replace access | Trust map complete and alternate administration tested | Identity/network change control | Identity and network platform teams | Disabled paths, reissued credentials/keys, AAA changes, active-session termination records | Use tested local break-glass identities and out-of-band paths; restore one path only under time-boxed incident exception |
| 4 — Reimage and restore infrastructure | Root/control-plane compromise confirmed or integrity cannot be established | Incident commander and service owner | Network and Linux recovery teams | Vendor image digests, configuration backups, rebuild logs, integrity and health results | Boot prior known-good supported image/configuration on redundant equipment if validation fails |
| 5 — Validate and close | All access paths replaced, independent evidence reconciles, and services are stable | Incident commander | Detection engineering, network, and Linux owners | 30-day Q01-Q05 re-hunt, AAA/config/flow reconciliation, no unexplained gaps, exception closure | Reopen scope and containment on any new indicator, evidence mismatch, or unauthorized trust path |
Continuity rule: preserve volatile evidence and verify alternate administration before isolation, reboot, credential replacement, device reload, or host rebuild.
Detection Coverage and Validation Evidence
Validation state: STATIC REVIEW PASSED after local structure/safety, maintained-field, CQL heuristic, provenance, and duplicate gates. This is not Falcon parsing, canary success, or deployment evidence.
| Technique | Coverage | Query / handoff | Evidence | Limitation |
|---|---|---|---|---|
| T1090 | Design | native evidence handoff | Source-backed behavior and non-CQL review | No portable endpoint query for this behavior |
| T1557 | Design | native evidence handoff | Source-backed behavior and non-CQL review | No portable endpoint query for this behavior |
| T1098.004 | Design | native evidence handoff | Source-backed behavior and non-CQL review | No portable endpoint query for this behavior |
| T1543.002 | Static | Q05 | Local static gates | Tenant parsing and baseline absent |
| T1070.002 | Static | Q04 | Local static gates | Tenant parsing and baseline absent |
| T1036 | Static | Q01, Q03 | Local static gates | Tenant parsing and baseline absent |
| Telemetry gap | Gap | H06 | Documented design handoff | Router GRE, PCAP, AAA, SNMP, and runtime/configuration divergence require device and independent collector telemetry. |
| Telemetry gap | Gap | H07 | Documented design handoff | tac_plus injection and credential-capture evidence requires memory, library-map, file, and AAA schema not assumed portable. |
Recorded evidence
- Every CQL card remains tenant-unverified and was not executed against Falcon.
- The offline tenant-validation dry run checks extraction and profile readiness only; it does not contact a tenant.
- IOC rows are bound to current hashed snapshots and require context before action.
- Next step: run each query manually in a safe one-hour window, confirm fields and semantics, then expand to the documented lookback.
Hunt Summary Ticket
TITLE: Fire Ant Trusted-Infrastructure Espionage hunt — v0.3 Draft SEVERITY: high — privileged infrastructure or root trust may be compromised SCOPE: Cisco IOS XR routers, TACACS servers, Linux management hosts, hypervisors, and trusted administrative paths; endpoint and independent infrastructure evidence HYPOTHESIS: H01 hunt; H02 hunt; H03 hunt; H04 hunt; H05 hunt; H06 gap; H07 gap QUERIES RUN: Q01 hunt; Q02 hunt; Q03 hunt; Q04 hunt; Q05 hunt; no alert-candidate query DO FIRST: Run Q04 over 30 days on Linux infrastructure hosts, then correlate tampering commands with independent AAA and configuration evidence. FINDINGS: GAPS: IOS XR router control-plane behavior requires vendor/device and independent collector telemetry; Falcon endpoint CQL cannot cover it directly.; TACACS process injection and memory evidence require host forensics or documented Linux telemetry not assumed portable.; Deleted-but-running processes and packet-triggered backdoors require memory/process-state acquisition beyond static CQL.; Local logs may be attacker-manipulated; every high-confidence conclusion needs independent evidence.; Actor-label overlap is not a detection condition and is not used to broaden IOC attribution. ACTIONS: preserve evidence; validate queries; assign platform, network, identity, and recovery owners OWNER: Incident Response / SOC / Infrastructure Platform / Network Security VERSION: v0.3 Draft · 2026-09-04 · STATIC REVIEW PASSED
Changelog
References
| ID | Publisher | Edition/date | Accessed | Use | URL |
|---|---|---|---|---|---|
| S01 | Sygnia | current cited edition | 2026-09-03T11:03:12Z | Current Fire Ant incident research and indicators | https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/ |
| S02 | Mandiant / Google Threat Intelligence Group | current cited edition | 2026-09-03T11:03:12Z | Independent behavior corroboration; no actor equivalence | https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers |
| S03 | CISA | current cited edition | 2026-09-03T11:03:12Z | Network-management and evidence hardening | https://www.cisa.gov/resources-tools/resources/network-infrastructure-security-guide |
| S04 | Cisco | current cited edition | 2026-09-03T11:03:12Z | TACACS authentication, authorization, and accounting authority | https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/200467-TACACS-Configuration-Guide.html |