A cyber espionage group linked to China, known as Fire Ant, has broadened its long-term campaign to include attacks on Cisco IOS XR routers, alongside targeting TACACS servers and Linux management systems. These devices are critical for routing, authentication, and network management within high-value infrastructures.
Expanding Attack Vectors
Sygnia, a firm specializing in incident response, discovered that Fire Ant transformed compromised routers into data collection hubs. These routers were used to intercept network traffic, acquire login credentials, and prevent the logging of activities, which are crucial for cybersecurity defense teams to trace back an attack.
The compromised routers allowed the hackers to gain insight into data moving across trusted network channels. Although Fire Ant’s exploration included scanning critical infrastructure networks, confirmed breaches were not established beyond connection attempts.
Overlap with Known Espionage Groups
Sygnia’s findings suggest that Fire Ant’s activities show significant overlap with the UNC3886 group, another China-linked espionage entity known for targeting virtualization platforms and network edge devices. However, Mandiant, the first to report on UNC3886, noted no direct technical similarities with other Chinese operations like Salt Typhoon and Volt Typhoon.
In 2025, Sygnia disclosed earlier activities of Fire Ant, emphasizing their initial focus on VMware environments before expanding into broader network layers. The investigation of the Cisco router breach began with an anomaly involving a GRE tunnel interface lacking proper configuration history.
Advanced Malware and Credential Theft
Fire Ant’s router malware was adeptly designed for the IOS XR control plane. It included a modified system library that filtered log messages and concealed the attacker’s tunnel configurations from administrators.
On TACACS servers, a specialized toolset named TacTap was identified, capable of injecting a malicious library into authentication processes to capture credentials. This technique, not previously documented, signifies a sophisticated evolution in Fire Ant’s cyber operations.
Additionally, Fire Ant employed a Linux backdoor dubbed BridgeAgent, which was disguised as a legitimate monitoring agent and utilized for command-and-control functions over encrypted channels.
Implications and Defensive Measures
Fire Ant’s actions underscore the necessity for treating routers, TACACS servers, hypervisors, and other network management hosts as primary forensic resources. Sygnia advises cross-referencing logs with other forms of evidence, such as memory and network configurations, to ensure comprehensive analysis.
As cyber threats continue to evolve, organizations must remain vigilant, updating their defense strategies to counteract sophisticated espionage techniques like those demonstrated by Fire Ant.
