Breaking
SecurityDeveloping Story

Cisco routers become covert spying tools

China-linked Fire Ant targets network gear, raising doubts about evidence integrity.

··2 hours ago·4 min read
black steel electronic device
Photo by Denny Bú on Unsplash

Security teams investigating intrusions typically trust the logs and telemetry generated by routers, switches, and authentication servers. New research from incident response firm Sygnia suggests that trust may be misplaced. The firm reports that a China-linked espionage group tracked as Fire Ant has moved beyond VMware environments to compromise Cisco IOS XR routers, using them to collect network traffic while actively suppressing evidence of its activity.

Targeting the network's core

According to Sygnia's findings, Fire Ant in 2026 set its sights on Cisco IOS XR routers, a platform commonly deployed in service provider and large enterprise networks. The attackers also compromised TACACS authentication infrastructure and Linux management hosts as they explored access to connected high-value environments. TACACS is a protocol widely used to control who can administer network devices, making it a prized target for attackers seeking to mask their movements.

The campaign builds on Sygnia research published last year that documented Fire Ant establishing deep persistence in VMware ESXi and vCenter environments. The latest activity shows the group extending that playbook into the infrastructure used to route traffic and administer enterprise networks. Sygnia detailed the findings in a report released this week.

Evidence under attack

Sygnia found attempts to suppress logging and conceal configuration activity on the affected network equipment. Evidence was also tampered with on compromised Linux systems. This goes beyond simply disabling a security tool; it strikes at the very records defenders rely on to reconstruct an attack.

If the system generating the evidence has itself been compromised, the absence of an alert or log entry can no longer be treated as proof that an action did not occur.

— Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services

The suppression of AAA requests, SNMP traps, and command output could leave gaps around administrator activity, configuration changes, and credential use. Grover said enterprises should avoid relying on a single device or management plane as the authoritative source of evidence. Critical telemetry should be exported to separately administered systems and checked against independent sources such as identity platforms and network-flow data.

The 'target behind the target' scenario

Sygnia described the operation as creating a potential “target behind the target” scenario, in which access to one organization’s trusted infrastructure could expose paths toward other high-value environments. Fire Ant probed systems associated with critical infrastructure, although the report does not establish that those critical-infrastructure systems were successfully compromised.

This approach reflects a broader interest among sophisticated espionage groups in occupying privileged positions inside enterprise networks. Control of network infrastructure can give attackers visibility into traffic and potential routes into systems connected through trusted links.

A recognized overlap

Sygnia assesses that Fire Ant’s activity strongly overlaps with publicly reported operations attributed to UNC3886, a China-nexus espionage cluster tracked by Mandiant. However, Sygnia has not treated the two as definitively identical. Mandiant has previously documented UNC3886 targeting network equipment and TACACS infrastructure while attempting to evade conventional monitoring.

The overlap matters because it suggests a recurring playbook: go after the systems that manage network access and administration, rather than endpoints. Grover cautioned that one campaign does not establish an industry-wide shift, but said it fits a broader pattern among sophisticated China-linked actors of targeting highly privileged infrastructure that may receive less consistent monitoring.

An infrastructure blind spot

Network infrastructure remains a blind spot for many security teams, according to Akshat Tyagi, associate practice leader at HFS Research. He said security teams have traditionally monitored endpoints and servers more closely than the systems connecting and administering them.

That gap is exactly what makes these targets attractive. Routers and authentication servers often sit outside the visibility of endpoint-focused security tools, and their logs are rarely scrutinized with the same rigor.

Treating infrastructure as Tier-0

For CISOs, the campaign is another reason to apply the same level of security scrutiny to network and authentication infrastructure as they do to endpoints and servers. Grover said TACACS and similar authentication systems should be treated as Tier-0 assets because compromising them can expose privileged credentials while weakening administrative audit trails.

Neil Shah, vice president for research at Counterpoint Research, said the same Zero Trust principles applied elsewhere in the enterprise should extend to this Tier-0 infrastructure, with organizations continuously checking its integrity rather than assuming trusted systems remain trustworthy.

“Zero Trust now has to span from software to hardware,” Shah said. That means hardening privileged authentication paths and applying tighter controls to administrative traffic and the software allowed to run on critical infrastructure.

Simplifying the blast radius

Tyagi said CISOs should also focus on containing what he described as the “blast radius of trust,” limiting how far an attacker can move if a trusted system or connection is compromised. That requires examining network links according to what they make reachable and separating sensitive environments where possible, rather than assuming a trusted connection is inherently safe.

Incident-response plans should assume routers or authentication servers themselves may be compromised. Organizations therefore need independently retained evidence and out-of-band access so that responders are not forced to rely on the same management infrastructure they are investigating.

Why it matters

The implications for defenders are stark. If an attacker can compromise the very devices that produce security telemetry, they can effectively blind the incident response team. The campaign suggests that the systems many organizations treat as reliable evidence sources — routers, switches, and authentication servers — may actually be the most dangerous point of failure. This could mean that even well-staffed security operations centers could miss attacks if they continue to trust network gear without independent verification. For CISOs, the takeaway is clear: treat network and authentication infrastructure as a first-class security concern, and build in mechanisms to cross-check evidence from sources outside the attacker's reach.

#fire-ant#cisco#tacacs#espionage#sygnia

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories