Published on August 31, 2026

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs


Severity

High

Detail

Sygnia researchers have disclosed details of an ongoing China-linked cyber espionage campaign tracked as Fire Ant, which has expanded from VMware virtualization environments to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts supporting high-value networks. The activity overlaps significantly with the tactics publicly attributed to UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network infrastructure, although Sygnia has not made a conclusive attribution.

Fire Ant leveraged compromised routers as network collection points, enabling the attackers to capture traffic, harvest administrator credentials, conduct reconnaissance, and suppress security telemetry. The actor also deployed Linux backdoors, rootkits, SSH implants, and credential-stealing malware to establish persistent access across management infrastructure.

The campaign demonstrates the risks associated with compromising network infrastructure, where attackers can gain both access to trusted environments and visibility into traffic traversing critical network paths.

How?

Fire Ant compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts to establish persistent access and collect sensitive network data. The campaign began with an unexplained GRE tunnel on a Cisco IOS XR router. The attackers used the compromised router for network reconnaissance and deployed custom IOS XR implants that suppressed security logs and concealed malicious tunnel configurations from administrators.

Fire Ant also used compromised routers to capture network traffic (PCAPs) and upload the data to external FTP servers. On TACACS servers, the TacTap toolkit injected a malicious library into the tac_plus authentication process to intercept and collect administrator credentials.

On Linux management hosts, the attackers deployed BridgeAgent, which masqueraded as a Zabbix monitoring agent and maintained persistence through a systemd service. Additional persistence was achieved using Medusa and REPTILE rootkits, custom SSH backdoors, and binaries disguised as legitimate security agents. The actor also attempted to erase evidence by suppressing router logs, SNMP traps, and authentication records, disabling SELinux, rewriting login histories, and removing privileged-command entries from system logs.

Fire Ant subsequently used the compromised infrastructure to scan and probe connected high-value environments, including critical infrastructure, although no confirmed compromise of those environments was identified.

Indicator of Compromises (IoCs)

The table below shows a selection of indicators of compromise (IoCs) associated with Fire Ant malicious activity.

TypeIndicatorDescription
SHA-136005f5e4398a1c62a2a9271eddfcc1b44b1ad00/usr/sbin/acppid TacTap injector
SHA-1955cd45a2f6f226a2fdf44b329af1c8dde90cb38/lib/libseconfd.so malicious injected library
SHA-1be6b27f429324a4af05a310d8ec9635e37c68a94/usr/bin/acpid Cisco IOS XR implant
SHA-11682b652a15bde732489f22809b0b7594c228fd3/pkg/bin/dhcpd_show_issu_status Cisco IOS XR implant
SHA-1b149fa3a34bd585e7a674a4fd9538437bd06f514/pkg/bin/hd Cisco IOS XR implant
Filename/var/log/[.]tacplus[.]acctFile used to store captured TACACS credentials
Filename/lib/libseconfd[.]soMalicious library injected into the tac_plus process
Filename/etc/rc[.]d/init[.]d/grub-rommonPersistence script associated with Cisco IOS XR implants
Filename/opt/[.]ICEauthorityEncrypted BridgeAgent configuration

Conclusion

The Fire Ant campaign demonstrates the risks of compromising network infrastructure and authentication systems as attackers can gain both privileged access and visibility into trusted network traffic. By targeting Cisco IOS XR routers, TACACS servers, and Linux management hosts, the actor was able to collect network data, steal administrator credentials, establish persistent access, and interfere with security telemetry.

The use of custom router implants, credential-stealing malware, rootkits, and log-tampering techniques also highlights the difficulty of detecting and investigating attacks when attackers compromise the infrastructure responsible for generating security evidence.

Source

https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html