China-Linked 'Fire Ant' Hackers Hijack Cisco Routers

Incident-response firm Sygnia said Monday that a China-linked espionage group it tracks as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers and TACACS+ authentication servers, converting trusted network infrastructure into a covert surveillance platform.
Sygnia's researchers said Fire Ant's tradecraft "strongly overlaps" with UNC3886, a China-nexus threat actor previously linked to attacks on VMware ESXi and vCenter environments, though the firm stopped short of a formal attribution. The 2026 findings build on Sygnia's initial disclosure of Fire Ant's VMware-focused activity in July 2025.
According to the report, the group used concealed GRE tunnels through compromised routers to observe traffic moving across trusted network paths. "When a threat actor controls routers, they do not only gain reach. They gain perspective," Sygnia researchers wrote.
To maintain access and avoid detection, the attackers deployed a credential-harvesting tool called TacTap that injects into the TACACS authentication process, a Linux backdoor named BridgeAgent disguised as a Zabbix monitoring agent, and the Medusa and REPTILE rootkits. The group also suppressed log messages, disabled SELinux, altered file timestamps, and ran its implants only during limited hours to reduce the chance of discovery.
Sygnia said Fire Ant used a "target behind the target" strategy, leveraging compromised trusted infrastructure — including Linux management hosts — to pivot into connected high-value networks over SSH, web, SMB/RPC and RDP. The firm reported observing connection attempts reaching toward critical infrastructure networks, though it said those were limited to scanning activity.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.