Cybersecurity

China-Linked 'Fire Ant' Hackers Hijack Cisco Routers

Published 1 min readBy NewUJ Editorial Desk

Updated new information added

China-Linked 'Fire Ant' Hackers Hijack Cisco Routers
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

Incident-response firm Sygnia said Monday that a China-linked espionage group it tracks as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers and TACACS+ authentication servers, converting trusted network infrastructure into a covert surveillance platform.

Sygnia's researchers said Fire Ant's tradecraft "strongly overlaps" with UNC3886, a China-nexus threat actor previously linked to attacks on VMware ESXi and vCenter environments, though the firm stopped short of a formal attribution. The 2026 findings build on Sygnia's initial disclosure of Fire Ant's VMware-focused activity in July 2025.

According to the report, the group used concealed GRE tunnels through compromised routers to observe traffic moving across trusted network paths. "When a threat actor controls routers, they do not only gain reach. They gain perspective," Sygnia researchers wrote.

To maintain access and avoid detection, the attackers deployed a credential-harvesting tool called TacTap that injects into the TACACS authentication process, a Linux backdoor named BridgeAgent disguised as a Zabbix monitoring agent, and the Medusa and REPTILE rootkits. The group also suppressed log messages, disabled SELinux, altered file timestamps, and ran its implants only during limited hours to reduce the chance of discovery.

Sygnia said Fire Ant used a "target behind the target" strategy, leveraging compromised trusted infrastructure — including Linux management hosts — to pivot into connected high-value networks over SSH, web, SMB/RPC and RDP. The firm reported observing connection attempts reaching toward critical infrastructure networks, though it said those were limited to scanning activity.

Report / request removal

Related

Comments

No comments yet. Be the first.