Researchers discovered that the Chinese Fire Ant hacking group has deployed a new tactic using invisible GRE tunnel interfaces on Cisco IOS XR routers to conduct espionage. The tunnels remain undetectable in running configurations and commit histories, reported between 31 August and 1 September 2026.
By September 2, 2026, researchers at Sygnia reported that the China-nexus actor Fire Ant expanded its long-running espionage campaign from VMware environments to target Cisco IOS XR routers and TACACS authentication servers, rewriting logs to remain undetected.