The Fire Ant espionage campaign has moved beyond servers and hypervisors, targeting Cisco routers, authentication systems and Linux management hosts to monitor traffic, steal credentials and hide its tracks.
A China-linked cyber-espionage campaign has taken an unusual turn: instead of simply breaking into computers, attackers are compromising network routers themselves and turning them into surveillance platforms.
Security researchers at Sygnia say the group tracked as Fire Ant has expanded its operations to Cisco IOS XR routers, TACACS authentication servers and Linux management hosts. Once inside, the attackers used compromised routers to capture network traffic, establish hidden connections and interfere with the logs that security teams normally rely on to investigate intrusions.
The significance goes beyond Cisco.
Routers sit at the center of corporate and telecommunications networks. They see traffic moving between systems, understand how different parts of an organization connect and often have privileged relationships with other infrastructure.
Compromising one can therefore give an attacker something much more valuable than access to a single computer: a view of the network itself.
The router becomes the attacker’s vantage point
Sygnia discovered the activity while investigating a compromised environment and found an unexplained GRE tunnel on a Cisco IOS XR router.
The tunnel did not appear in the normal configuration or commit history.
Further investigation revealed malware specifically designed to operate inside the router’s IOS XR environment. The attackers were not treating the device as a simple gateway. They were using it as an operational platform.
According to Sygnia, compromised routers were used to collect network traffic and send packet captures to external infrastructure. In some cases, attackers were able to observe traffic from multiple interfaces, giving them a much broader picture of the targeted environment.
That is an important distinction.
Breaking into an employee’s laptop might expose that person’s files and credentials.
Breaking into a router can reveal who is communicating with whom, which systems are connected, how administrators access infrastructure and where sensitive networks are located.
For an espionage operation, that information can be enormously valuable.
Sygnia describes the strategy as a “target behind the target” approach: the compromised infrastructure becomes a bridge toward other environments connected through trusted relationships.
Fire Ant is also attacking the systems that record the evidence
The router compromise was only one part of the operation.
Sygnia also found evidence that Fire Ant targeted TACACS authentication servers, which are commonly used by administrators to authenticate when managing network equipment.
This creates another layer of risk.
If attackers compromise the authentication infrastructure, they can potentially obtain administrator credentials and weaken the systems that record privileged activity.
Researchers found something even more unusual: a malicious implant injected into a running TACACS+ authentication daemon.
That means the attackers were not simply modifying files on disk. They were manipulating the running process itself, making traditional file-integrity checks much less useful.
The effect is potentially devastating for incident response.
Security teams investigating an intrusion often begin by asking a simple question: What did the attacker do?
They reconstruct the answer from logs.
If the attacker controls the infrastructure generating those logs, the evidence itself can no longer be trusted.
The malware was built specifically for Cisco’s environment
Another detail makes the campaign stand out.
The malware discovered by Sygnia was not simply generic Linux malware copied onto a router.
The implants interacted directly with IOS XR-specific components, including routing functions, syslog, VRF resolution, AAA services and management interfaces.
That level of specialization suggests the attackers understand the operating environment they are targeting.
Researchers identified multiple components serving different purposes, including persistence, traffic collection, command manipulation and covert communication.
One component was disguised as a legitimate startup service, while another implant was designed to maintain access to Linux management infrastructure.
The campaign also used techniques designed to make the compromise less visible to administrators.
The attackers could manipulate command output and suppress certain logging information, meaning a normal administrator checking the router might not immediately see what was happening.
This is precisely the type of operation that makes network-device compromises so difficult to detect.
The router may continue doing its normal job.
Packets still move.
Users still connect.
Applications still work.
But underneath that normal activity, the device may also be providing an attacker with a privileged observation point.
The campaign has moved beyond VMware
Fire Ant is not a completely new threat.
Sygnia previously tracked the group targeting VMware virtualization environments, but the latest investigation shows a significant expansion into what the researchers call the trusted infrastructure layer.
That includes routers, authentication systems and management hosts — systems that organizations often treat as foundational and therefore highly trusted.
The change matters because traditional endpoint-focused security can miss this type of intrusion.
A company might have strong protection on employee laptops and servers while paying considerably less attention to the underlying network equipment.
Attackers know that.
A compromised router can also provide a quieter route into other systems because it already sits in a privileged location.
Sygnia says the 2026 activity included scanning and connection attempts toward high-value environments, including infrastructure associated with critical systems. The researchers did not publicly identify the affected organizations.
There is also an important caveat: the attribution to China is based on the security researchers’ assessment. Fire Ant has been described as a China-nexus actor, and some researchers have noted similarities with the group known as UNC3886, but attribution is not presented as absolute proof of government direction.
Why this could become a bigger problem
The most worrying part of the Fire Ant campaign is not necessarily the specific Cisco router involved.
It is the strategy.
Network infrastructure has traditionally been treated as the machinery that makes digital systems communicate.
Fire Ant demonstrates how that machinery can itself become an intelligence platform.
A compromised router can see traffic.
An authentication server can see administrators.
A management host can provide access to other systems.
Together, they form a much more powerful position than a single compromised endpoint.
And because these devices are often trusted by the rest of the network, attackers may not need to smash through every layer of security.
They can simply sit inside the infrastructure that everyone else already trusts.
For defenders, that changes the question from “Have we secured our computers?” to something much broader:
Can we still trust the devices that connect those computers together?
The Fire Ant campaign suggests that, for some organizations, the answer may already be no.
by The Tech Spot Editorial Team
