Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
exploitIncidentVulnerability

Fire Ant Espionage Campaign Hijacks Cisco Routers

By ogwatermelon
September 1, 2026 5 Min Read
0
August 31, 2026

A China-nexus cyber espionage actor tracked as Fire Ant has evolved beyond hypervisor compromise to hijack Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Consequently, the group turns trusted network infrastructure into covert collection platforms capable of harvesting credentials, capturing traffic, and probing paths toward connected high-value environments including critical infrastructure.

What Happened: Fire Ant Hijacks Cisco Routers for Espionage and Lateral Movement

Fire Ant first surfaced in 2025 when Sygnia disclosed the group’s exploitation of VMware ESXi and vCenter environments. However, by 2026 the actor had shifted tactics dramatically. Moreover, investigators from Sygnia discovered an active GRE tunnel interface on a Cisco IOS XR router that had no matching configuration or commit history.

This anomaly led to a deeper investigation revealing that Fire Ant had turned edge routers into operational spying platforms. The actor deployed custom malware purpose-built for the Cisco IOS XR control plane. Therefore, the routers became vantage points for observing traffic moving through trusted network paths.

The campaign also targeted Terminal Access Controller Access-Control System servers to intercept authentication flows. Furthermore, the actor compromised Linux management hosts to stage additional tooling and establish persistent reverse-shell access. The scope extended beyond the initially compromised organization, suggesting Fire Ant sought a bridge into connected networks.

Technical Details of the Router Compromise

Fire Ant’s router toolkit was not generic Linux malware. Instead, each component interacted directly with IOS XR-specific functions for logging, command execution, routing, VRF resolution, AAA, and Telnet management.

The acpid Implant and Log Suppression

The primary implant, disguised as /usr/bin/acpid, embedded a modified IOS XR syslog library. In addition, the malware selectively suppressed log messages by checking for the string “Health” before forwarding them. When the condition was not met, the wrapper returned a success-like value without forwarding the message.

The implant also supported interactive shell access. Furthermore, it contained logic to unset shell-history environment variables, erasing evidence of operator commands.

Outbound Telnet and GRE Tunneling

A second component masquerading as /pkg/bin/dhcpd_show_issu_status provided outbound connectivity. It contained a hardcoded external IP address and Telnet client functionality. Moreover, it imported IOS XR-specific routing and VRF libraries to operate natively within the router’s networking context.

Fire Ant established concealed GRE tunnels between compromised routers and legacy Linux systems. From these staging nodes, the actor probed connected networks over ports commonly used for SSH, web services, SMB, and RDP.

Command-Output Manipulation

Reverse engineering of the /pkg/bin/hd component showed that Fire Ant modified the IOS XR command execution path. Specifically, the actor appended | exclude filters to show commands before forwarding them to the normal shell routine. This tactic hid tunnel-related configuration from administrators inspecting the device.

TACACS Credential Theft with TacTap

On TACACS servers, Sygnia identified a novel credential-collection toolset it tracks as TacTap. The mechanism is more sophisticated than ordinary credential theft.

An injector named /usr/sbin/acppid loaded a malicious library into the running tac_plus authentication process. The library hooked the functions that accept new connections. Then it passed live session handles to a second process over a local Unix socket.

The captured credentials were written to /var/log/.tacplus.acct and lightly obfuscated with a single-byte XOR key of 0xEF. To Sygnia’s knowledge, this specific tac_plus library-injection technique has not been publicly described before.

BridgeAgent and Linux Management Host Compromise

On the GRE-connected Linux host, investigators found a previously undocumented backdoor called BridgeAgent. The implant masqueraded as a Zabbix monitoring agent and persisted via a zabbix_agent.service systemd unit running as root.

BridgeAgent stored encrypted configuration at /opt/.ICEauthority and polled actor-controlled infrastructure over TLS on port 443. In addition, the implant launched secondary binaries for reverse-shell connectivity.

Resilient Access Layer

Across Linux management hosts, Fire Ant built a durable access layer using the open-source Medusa and REPTILE rootkits. The actor also deployed custom SSH backdoors and binaries renamed to impersonate SentinelOne and Cybereason endpoint security agents.

Several components were planted in 2025 and reused for hands-on activity in 2026. At least one backdoor kept running in memory after its file had been deleted from disk.

Business and Operational Impact

The Fire Ant campaign carries significant implications for organizations operating interconnected networks. By compromising routers, the actor gains more than reach. It gains perspective.

  • Credential Exposure: TACACS servers sit at administrative chokepoints. Compromising this layer allows harvesting credentials as they are used across network devices.
  • Traffic Collection: Router-based PCAP captures expose internal topology, management connections, authentication flows, and traffic patterns between connected environments.
  • Lateral Movement Risk: The “target behind the target” model means compromised infrastructure can bridge into connected high-value networks, including critical infrastructure.
  • Forensic Integrity: Fire Ant systematically tampered with logs, rewritten login-history records, and suppressed SNMP traps. Therefore, investigators cannot rely on a single telemetry source.
  • Supply Chain Exposure: Third-party environments connected through trusted infrastructure relationships face elevated risk.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Validate Router Configuration: Compare running configurations against operational state. Look for unexplained tunnel interfaces or VRF entries.
  2. Hunt for GRE Tunnels: Search for active GRE interfaces without matching commit history or configuration records.
  3. Audit TACACS Servers: Monitor tac_plus processes for injected libraries or unexpected Unix sockets.
  4. Inspect Linux Management Hosts: Look for masqueraded services, deleted-but-running processes, and SELinux disabling.
  5. Correlate Evidence Sources: Validate logs against memory, disk, network, authentication, and configuration evidence.

Strategic Improvements

Treat routers, TACACS servers, hypervisors, jump hosts, and management appliances as first-class security assets. Moreover, apply the same monitoring, hardening, and incident-response readiness as traditional endpoints.

Implement network segmentation to limit router visibility into adjacent environments. Furthermore, enforce multi-factor authentication for all administrative access to network infrastructure.

Bottom line: Fire Ant demonstrates that mature espionage actors now target the infrastructure layer that makes other systems reachable, trusted, and observable. Organizations must shift their defensive focus from endpoints alone to the control-plane systems that govern network connectivity and administrative trust.

Incident Summary

Threat Actor: Fire Ant (overlaps with UNC3886)
Origin: China-nexus espionage group
Targets: Cisco IOS XR routers, TACACS servers, Linux management hosts, VMware hypervisors
Disclosure Date: August 31, 2026
Initial Reporting: July 2025 (VMware exploitation)
Key Malware: acpid, dhcpd_show_issu_status, hd, TacTap, BridgeAgent, REPTILE, Medusa
Attack Vectors: GRE tunneling, log suppression, credential interception, command-output filtering, rootkit deployment
Patch Status: No specific CVE; incident response and hardening recommended
Attribution Confidence: Strong overlap with UNC3886; no conclusive attribution by Sygnia

References

  1. Sygnia, “Fire Ant Evolves: From Hypervisors to Trusted Infrastructure,” August 2026, https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/, accessed August 31, 2026.
  2. Sygnia, “Fire Ant: A Deep Dive Into Hypervisor-Level Espionage,” July 2025, https://www.sygnia.co/blog/fire-ant-a-deep-dive-into-hypervisor-level-espionage/, accessed August 31, 2026.
  3. BleepingComputer, “Chinese Fire Ant Hackers Turn Cisco Routers Into Spying Platforms,” August 31, 2026, https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/, accessed August 31, 2026.
  4. The Hacker News, “China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs,” August 31, 2026, https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html, accessed August 31, 2026.
  5. Google Cloud / Mandiant, “China-Nexus Espionage Targets Juniper Routers,” https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers, accessed August 31, 2026.

Tags:

ExploitIncidentVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Socket Uncovers 19 Malicious Chrome and Edge Extensions Stealing Crypto Wallets and Credentials

Next

Cronos Tectonic Exploit Drained 4 Million in 20 Minutes

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.