China-Linked Fire Ant Expands Espionage to Cisco Network Equipment

By September 2, 2026, researchers at Sygnia reported that the China-nexus actor Fire Ant expanded its long-running espionage campaign from VMware environments to target Cisco IOS XR routers and TACACS authentication servers, rewriting logs to remain undetected.

12 reports · 11 independentother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

China-linked Fire Ant targets Cisco routers for espionage

kite:cybersecurityother29d ago kagi ↗

Sygnia said the China-nexus actor tracked as Fire Ant expanded a long-running espionage campaign beyond VMware environments to Cisco IOS XR routers, TACACS authentication servers and Linux management hosts used to route, authenticate and manage high-value networks [thehackernews.com#1][cybersecuritydive.com#1][bleepingcomputer.com#1]. The incident response firm said the attackers used compromised

🤖 China-linked espionage group 'Fire Ant' expanded its campaign beyond VMware: now compromising Cisco IOS XR routers, TACACS servers and Linux management hosts to steal credentials and blind security

mastodon:infosec-exchangeother29d ago kagi ↗

🤖 China-linked espionage group 'Fire Ant' expanded its campaign beyond VMware: now compromising Cisco IOS XR routers, TACACS servers and Linux management hosts to steal credentials and blind security logs, per Sygnia incident response. 🔗 https:// thehackernews.com/2026/08/chin a-linked-fire-ant-hijacks-cisco.html # CyberSec # Espionage # Cisco # InfoSec

China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, then rewrote the logs to stay invisible. The routers logged only "Health" heartbeats, so liveness checks passed while everyth

mastodon:infosec-exchangeother29d ago kagi ↗

China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, then rewrote the logs to stay invisible. The routers logged only "Health" heartbeats, so liveness checks passed while everything else vanished. Off-host logging catches it. https:// suriq.io/blog/fire-ant-cisco-r outer-tacacs-credential-theft # Detection # Phishing # infosec # cybersecurity

Sygnia's incident response report on Fire Ant reveals a significant tactical shift. The China-linked espionage group has moved beyond VMware ESXi to compromise Cisco IOS XR routers, TACACS+ servers, a

mastodon:infosec-exchangeother29d ago kagi ↗

Sygnia's incident response report on Fire Ant reveals a significant tactical shift. The China-linked espionage group has moved beyond VMware ESXi to compromise Cisco IOS XR routers, TACACS+ servers, and Linux management hosts — embedding persistence in the routing and authentication layers of enterprise networks. # FireAnt # CiscoSecurity # ThreatIntelligence # IncidentResponse https:// cyberworld

Fire Ant hackers repurpose Cisco routers for espionage Chinese APT group exploits GRE tunnels on IOS XR devices to exfiltrate data. https:// hostingpaper.com/article/fire- ant-hackers-repurpose-cisco-

mastodon:mstdn-socialother29d ago kagi ↗

Fire Ant hackers repurpose Cisco routers for espionage Chinese APT group exploits GRE tunnels on IOS XR devices to exfiltrate data. https:// hostingpaper.com/article/fire- ant-hackers-repurpose-cisco-routers-for-espionage # Security # Vulnerabilities

Fire Ant, a China-linked espionage group previously seen targeting # VMware , is now also attacking Cisco routers and authentication servers. Researchers say it collected credentials and traffic while

mastodon:mstdn-socialother28d ago kagi ↗

Fire Ant, a China-linked espionage group previously seen targeting # VMware , is now also attacking Cisco routers and authentication servers. Researchers say it collected credentials and traffic while manipulating logs to conceal its presence. Listen/Read: https:// hackread.com/china-fire-ant-ha ckers-cisco-routers-tacacs-espionage/ # CyberSecurity # CyberEspionage # Cisco # FireAnt # China # Cybe

"Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware" "Fire Ant is now targeting routers, authentication ser

mastodon:infosec-exchangeother28d ago kagi ↗

"Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware" "Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones." https://www. techradar.com/pro/security/cis co-routers-are-being-turned-into-surveillance-vantage-points-to-hoover-up-data-on-trusted-

⚪️ Chinese Fire Ant Group Uses Cisco Routers for Espionage 🗨️ Researchers at Sygnia have reported on new activity by the Chinese hacking group Fire Ant. Previously, the group targeted VMware hypervis

mastodon:infosec-exchangeother27d ago kagi ↗

⚪️ Chinese Fire Ant Group Uses Cisco Routers for Espionage 🗨️ Researchers at Sygnia have reported on new activity by the Chinese hacking group Fire Ant. Previously, the group targeted VMware hypervisors, but it has now shifted its focus to other infrastructure components: Cisco IOS XR routers, TACACS authentication servers, and… 🔗 https:// hackmag.com/news/fire-ant-cisc o?utm_source=mastodon&utm