By September 2, 2026, researchers at Sygnia reported that the China-nexus actor Fire Ant expanded its long-running espionage campaign from VMware environments to target Cisco IOS XR routers and TACACS authentication servers, rewriting logs to remain undetected.
12 reports · 11 independentother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Sygnia said the China-nexus actor tracked as Fire Ant expanded a long-running espionage campaign beyond VMware environments to Cisco IOS XR routers, TACACS authentication servers and Linux management hosts used to route, authenticate and manage high-value networks [thehackernews.com#1][cybersecuritydive.com#1][bleepingcomputer.com#1]. The incident response firm said the attackers used compromised
China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, then rewrote the logs to stay invisible. The routers logged only "Health" heartbeats, so liveness checks passed while everything else vanished. Off-host logging catches it. https:// suriq.io/blog/fire-ant-cisco-r outer-tacacs-credential-theft # Detection # Phishing # infosec # cybersecurity
Sygnia's incident response report on Fire Ant reveals a significant tactical shift. The China-linked espionage group has moved beyond VMware ESXi to compromise Cisco IOS XR routers, TACACS+ servers, and Linux management hosts — embedding persistence in the routing and authentication layers of enterprise networks. # FireAnt # CiscoSecurity # ThreatIntelligence # IncidentResponse https:// cyberworld
Fire Ant hackers repurpose Cisco routers for espionage Chinese APT group exploits GRE tunnels on IOS XR devices to exfiltrate data. https:// hostingpaper.com/article/fire- ant-hackers-repurpose-cisco-routers-for-espionage # Security # Vulnerabilities
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs https:// thehackernews.com/2026/08/chin a-linked-fire-ant-hijacks-cisco.html
Fire Ant, a China-linked espionage group previously seen targeting # VMware , is now also attacking Cisco routers and authentication servers. Researchers say it collected credentials and traffic while manipulating logs to conceal its presence. Listen/Read: https:// hackread.com/china-fire-ant-ha ckers-cisco-routers-tacacs-espionage/ # CyberSecurity # CyberEspionage # Cisco # FireAnt # China # Cybe
China-Linked Fire Ant Turned Cisco Routers, TACACS Servers Into Espionage Platforms https:// thecyberexpress.com/cisco-rout ers-tacacs-servers-espionage/
"Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware" "Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones." https://www. techradar.com/pro/security/cis co-routers-are-being-turned-into-surveillance-vantage-points-to-hoover-up-data-on-trusted-
⚪️ Chinese Fire Ant Group Uses Cisco Routers for Espionage 🗨️ Researchers at Sygnia have reported on new activity by the Chinese hacking group Fire Ant. Previously, the group targeted VMware hypervisors, but it has now shifted its focus to other infrastructure components: Cisco IOS XR routers, TACACS authentication servers, and… 🔗 https:// hackmag.com/news/fire-ant-cisc o?utm_source=mastodon&utm