Daily Security Intel

Archives
Log in
Subscribe
September 1, 2026

[SecurityIntel] 01 Sep | Chinese Fire Ant Hackers Hijack Cisco Routers

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, September 01, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Chinese Fire Ant Hackers Hijack Cisco Routers

CRITICAL

5

C2 IPs

52

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by sophisticated infrastructure hijacking, including Chinese state-sponsored group Fire Ant backdooring Cisco IOS XR routers with unauthorized GRE tunnels, and the Nightmare Eclipse group deploying the 'HardBreacher' exploit against Kaspersky Endpoint Security. Additionally, ransomware operators like Aurora are leveraging AI coding assistants like Cursor to accelerate network intrusion, while critical code injection flaws in ServiceNow and an arbitrary file read flaw in Ruby on Rails demand immediate patching. Organizations must also defend against social engineering campaigns, such as Microsoft Teams-based voice phishing and fake CAPTCHA prompts deploying reverse tunnels.

■ CRITICAL STORIES

HIGH#1

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials

The China-nexus threat actor Fire Ant has expanded its cyber espionage campaign to target Cisco IOS XR routers, TACACS servers, and Linux hosts, establishing unauthorized GRE tunnels and blinding security logs to evade detection.

CRITICAL#2

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

Attackers are actively targeting ServiceNow platforms using three critical code injection flaws that allow remote code execution and unauthorized data manipulation, requiring immediate patching.

HIGH#3

Nightmare Eclipse Drops 'HardBreacher' Kaspersky Product Exploit

A highly targeted campaign is leveraging a newly discovered exploit named 'HardBreacher' against Kaspersky Endpoint Security, allowing attackers to achieve privilege escalation and remote code execution.

HIGH#4

McKesson Confirms Major Data Breach After ShinyHunters Extortion

Healthcare giant McKesson confirmed a significant cyber incident involving a third-party application, with the ShinyHunters group claiming the theft of 284 million patient and corporate records.

■ CVEs IDENTIFIED

[CVE-TBD]

Kaspersky Endpoint Security — Remote Code Execution and Privilege Escalation via HardBreacher exploit

Critical

[CVE-TBD]

ServiceNow Platform — Code Injection leading to Remote Code Execution

Critical

[CVE-TBD]

Ruby on Rails — KindaRails2Shell Arbitrary File Read leading to Remote Code Execution

Critical

[CVE-TBD]

Cisco IOS XR — Unauthorized GRE tunnel creation and credential theft

Critical

■ THREAT ACTORS

Fire Ant

APT

Hijacking Cisco IOS XR routers, TACACS servers, and Linux management hosts to steal credentials and blind logs

ShinyHunters

Cybercrime / Extortion

Claiming theft of 284 million records from McKesson

Rhysida

Ransomware

Attacking Berlin city administration and demanding ransom

■ ATT&CK TTPs

T1572
Protocol Tunneling | Chinese Fire Ant actors established unauthorized GRE tunnels on Cisco IOS XR routers.
T1566.002
Phishing: Spearphishing Link | Guildma (Astaroth) distributed via Brazilian Portuguese emails; Spring Ring campaign used MS Teams voice phishing.
T1204.002
User Execution: Malicious File | TerminalFix attacks used fake Cloudflare CAPTCHAs to trick users into running PowerShell commands.
T1036
Masquerading | Silver Fox signed ValleyRAT as adware to bypass AV; DPRK actors posed as healthcare and sales job seekers.
T1070
Indicator Removal on Host | Fire Ant actors blinded security logs on compromised Cisco routers.
T1588.002
Obtain Capabilities: Tool | Aurora ransomware operators leveraged SpaceX's Cursor AI coding assistant to breach networks.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

ServiceNow ServiceNow Platform — Three critical code injection vulnerabilities allowing arbitrary code execution — SecurityWeek

[P1 PATCH NOW]≤24h

Kaspersky Endpoint Security — "HardBreacher" exploit allowing remote code execution and privilege escalation — SecurityWeek

[P1 PATCH NOW]≤24h

Ruby on Rails Web Framework — "KindaRails2Shell" arbitrary file read vulnerability allowing remote code execution — SecurityWeek

[P2 PATCH NOW]≤72h

Cisco IOS XR Router — Fire Ant actors exploiting routers to create unauthorized GRE tunnels and steal credentials — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch ServiceNow instances immediately to remediate three critical code injection vulnerabilities ([CVE-TBD]) that permit remote code execution.
2[P1] Apply security updates to Kaspersky Endpoint Security to mitigate the "HardBreacher" exploit ([CVE-TBD]) used by Nightmare Eclipse.
3[P1] Audit and update Ruby on Rails environments to patch the "KindaRails2Shell" arbitrary file read vulnerability ([CVE-TBD]).
4[P2] Inspect Cisco IOS XR routers for unauthorized GRE tunnel interfaces and anomalous configurations linked to Fire Ant activity.
5[P2] Implement application controls to restrict unauthorized developer tools like Cursor AI, which are being abused by Aurora ransomware operators.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 31 Aug | TerminalFix ClickFix attacks deploy reverse-tunnel backdoors.
Powered by Buttondown, the easiest way to start and grow your newsletter.