A China-linked cyber espionage group known as Fire Ant has expanded its operations by targeting trusted network infrastructure instead of focusing only on individual computers. According to cybersecurity firm Sygnia, the group compromised Cisco IOS XR routers, TACACS authentication servers and Linux management systems used to connect and manage high-value environments. The activity represents an evolution from Fire Ant’s earlier attacks on VMware ESXi and vCenter systems. Investigators found that the attackers used these trusted systems to maintain access, collect information and explore routes toward other connected networks.

One of the most important findings involved compromised Cisco IOS XR routers. Fire Ant turned the routers into collection platforms that could capture network traffic while also helping the attackers hide their activity from defenders. Investigators discovered a GRE tunnel on a router even though there was no matching running configuration or commit history explaining how it appeared. The attackers also modified router functions so that certain logs and command outputs could be hidden from administrators, making the device’s normal records less reliable during an investigation.

The attackers also targeted TACACS servers, which are commonly used to authenticate administrators accessing network devices. Sygnia identified a credential-collection toolset called TacTap that injected a malicious library into the running tac_plus authentication process. This allowed Fire Ant to intercept accepted authentication sessions and collect credential information from legitimate administrative connections. The collected data was stored in a file and lightly obfuscated using a single-byte XOR key, showing that the group was targeting the authentication layer itself rather than simply trying to steal passwords through traditional methods.

Fire Ant also created several ways to maintain long-term access to compromised Linux management systems. Sygnia identified a backdoor called BridgeAgent that disguised itself as a Zabbix monitoring agent and used a systemd service to maintain root-level persistence. Other tools included Medusa-related rootkits, custom SSH backdoors and packet-triggered backdoors designed to activate only when specific network traffic was detected. Some malicious components had been planted during 2025 and were still being used for activity in 2026, while at least one backdoor remained active in memory even after its file had been removed from the system.

Another major concern was the group’s effort to manipulate security evidence. Fire Ant suppressed router logs, SNMP traps and authentication-related information while also changing command output that administrators normally use to inspect network devices. On Linux systems, investigators found evidence of log manipulation, disabled SELinux, altered login-history records and deleted files whose processes could continue running in memory. This meant defenders could no longer assume that a single log source accurately represented what had happened, making investigations dependent on checking memory, disk, network, authentication and configuration evidence together.

Sygnia believes the activity strongly overlaps with public reporting about UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network-edge infrastructure, although the company has not made a conclusive attribution. Fire Ant’s activity against connected high-value environments was mainly observed through scanning and connection attempts, rather than confirmed compromises of those networks. The larger warning is that routers, authentication servers and management hosts can become the “target behind the target,” giving attackers visibility and trusted access into other environments. The investigation shows why these often-overlooked systems need the same level of security and forensic attention as the systems that directly store sensitive information.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news