The China-nexus threat actor "Fire Ant" is executing a "compute hijacking" campaign by deploying AI/ML frameworks, such as PyTorch and TensorFlow, directly onto compromised victim infrastructure. By targeting VMware hypervisors, Cisco IOS XR routers, and Linux-based management hosts, the actor utilizes the victim's local computational resources to process AI workloads. This strategy bypasses traditional egress monitoring and Data Loss Prevention (DLP) solutions by eliminating the need to communicate with external AI service providers. The campaign facilitates deep lateral movement via compromised TACACS authentication servers and management planes, enabling high-stealth persistence and automated, AI-driven exploitation of core network layers.
-
Infrastructure Targeting & Initial Access
- Compromise of Cisco networking hardware (routers and switches) to establish initial persistence and facilitate network traversal.
- Abuse of VMware hypervisors to host unauthorized virtual machines or containers dedicated to AI model execution.
- Targeting of Linux-based orchestration hosts to deploy unauthorized AI/ML frameworks and specialized LLM runtimes.
-
AI Workload Deployment & Evasion
- Local execution of AI models to eliminate dependencies on external AI APIs, effectively bypassing egress traffic monitoring.
- Masking malicious activity as legitimate administrative traffic by operating within core network management layers.
- Minimization of network footprint by reducing the frequency of external C2 callbacks during intelligence synthesis.
-
Impact of Compute Hijacking
- Resource exhaustion leading to significant degradation of legitimate business services due to heavy, unauthorized AI processing.
- Bypassing of Data Loss Prevention (DLP) solutions as computational traffic remains internal to the victim's perimeter.
- Unauthorized consumption of high-performance GPU and CPU resources within cloud and on-premise virtualized environments.
-
Lateral Movement & Persistence Mechanisms
- Exploitation of TACACS servers to gain centralized control over administrative authentication and access management.
- Deep penetration into sensitive network segments through the manipulation of trusted network management tools.
- Use of compromised management planes to facilitate automated reconnaissance and accelerated exploitation lifecycles.
-
Mitigation & Defensive Posture
- Implement strict monitoring for anomalous CPU, GPU, and RAM spikes within cloud and virtualized environments.
- Harden VMware hypervisor configurations and apply latest security patches to Cisco IOS XR systems.
- Enhance auditing of TACACS and administrative logs to identify unusual login patterns or unauthorized credential usage.
Related posts
- eSecurity Planet — Google Finds Chinese Hackers Running AI on Compromised Networks
- Sygnia — Sygnia Reveals New Activity by China-Nexus Threat Actor Fire Ant Targeting Trusted Infrastructure
- Industrial Cyber — Sygnia highlights Fire Ant risks from compromised routers, authentication systems in critical infrastructure
- Patriotla
- Nationalcioreview
- Ground
- Tmcnet
- Networking
- Thehackernews
- Realground
- Rack2cloud
- Darkreading
- Cyberflorida
- Apt