BTC$84,092-0.70% LTC$68.37+1.06% XMR$532.84-1.70%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 1, 2026 · 4 min read · Original story

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks
China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

China-based hackers used an array of methods to compromise popular Cisco routers and use them as a jumping off point to monitor organizations, steal credentials and break into other organizations.

In its latest report on a hacking operation it calls “Fire Ant,” cybersecurity firm Sygnia detailed a string of breaches that alarmed defenders due to its sophistication and effectiveness.

“Fire Ant didn’t just compromise systems. It compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure many organizations overlook as legacy technology became the attacker’s vantage point for reach, visibility, and control,” said Asaf Perlman, director of incident response at Sygnia.

“That is what makes this research so important: the significance extended beyond the initially compromised environment, as the affected infrastructure could provide a path toward other connected high-value environments.”

Sygnia said Fire Ant overlaps with a group Google Cloud’s Mandiant unit called UNC3886 — which was implicated in a string of attacks on prominent strategic organizations from 2022 to 2024.

Sygnia researchers said they saw Fire Ant hackers take over infrastructure and use those systems to collect intelligence and credentials before building durable access and concealing their activity.

The Israel-based company said the recent activity shows the actors are no longer focused only on endpoints, servers or cloud workloads. They want to target the infrastructure that sits between environments: routers, hypervisors, access appliances, Linux management hosts, and the systems that “create trust, reachability, and visibility.”

The latest campaign tracked by Sygnia focuses on attacks targeting Cisco IOS XR routers. The company uncovered new tools the group used for persistence and to collect critical credentials that enabled wider access to an organization.

The attackers also hid logs and took other measures to manipulate potential evidence of their activity, often deleting files and tampering with firewall rules.

Sygnia noted that after reporting on Fire Ant in 2025, the group remained active in 2026, evolving beyond compromising hypervisors. The 2026 compromises were seen to have impacted both victims and third-party environments — exploiting infrastructure relationships to breach high-value networks and critical infrastructure. Sygnia did not name the organizations impacted by the campaign.

Routers provide ‘perspective’

The malware discovered during the campaign was built specifically to control routers and modify them so they would be more manageable for the hackers’ needs.

Fire Ant actors were seen capturing traffic from multiple Cisco routers and uploading data to external infrastructure. They were not satisfied with one point of access, opting to get network vantage points “from across the environment.”

This gave the attackers a broader view of how systems, administrators, and connected networks interacted.

“This activity reinforces one of the core observations from the investigation: when a threat actor controls routers, they do not only gain reach. They gain perspective,” the researchers wrote.

“Fire Ant used network infrastructure to observe the environment from the inside, collecting information that could support lateral movement, credential targeting, and cross-network access planning.”

The actors became adept at compromising specific servers called TACACS that serve as a de facto administrative checkpoints. They authenticate users, authorize commands and record activity, the researchers said.

Compromising this layer allowed the threat actors to harvest credentials as they were used, observe administrative activity and create ambiguity between legitimate accounts and malicious activity.

Sygnia warned that their report illustrated that routers, hypervisors and more need to be treated as “first-class” security forensic assets requiring monitoring, hardening and incident response readiness.

Governments and cybersecurity companies have long warned that Chinese state-backed groups have targeted Cisco firewalls and routers. In 2024, Volt Typhoon — a Chinese government espionage unit previously implicated in several high-profile incidents involving U.S. critical infrastructure organizations — was seen targeting end-of-life Cisco routers and network devices in the U.S., U.K. and Australia.

Last year, defenders said more than 1,000 Cisco network devices were targeted by Chinese actors as part of the Salt Typhoon campaign.

Between September and December 2025, Palo Alto Networks’ Unit 42 and the federal cyber defense agency repeatedly warned that China-based hackers were attacking Cisco Adaptive Security Appliances (ASA) — popular devices used by governments and large businesses to consolidate several different security tasks into a single appliance.

Several experts said Sygnia’s latest findings were instructive because of what it showed about the threat actors’ objectives. Andrew Obadiaru, vice president at Cobalt, said the thing that stood out most was how much effort Fire Ant put into staying invisible on infrastructure defenders rarely watch closely.

The devices being targeted are typically outside of the coverage of security tools and are attractive because they don't trigger alerts, he said.

“This pattern of long-dwell, infrastructure-level access lines up with what we've seen from other Chinese espionage clusters targeting telecom and network infrastructure, and it argues for continuous validation of trust relationships across management infrastructure rather than periodic checks,” Obadiaru said.

References in this story

  1. Fire Ant Evolves: From Hypervisors to Trusted Infrastructure | Sygnia www.sygnia.co Discover Sygnia’s investigation into Fire Ant, an advanced cyber-espionage campaign breaching VMware ESXi, vCenter, and network appliances. Learn how the attackers bypassed traditional defenses with hypervisor-level…
  2. Cloaked and Covert: Uncovering UNC3886 Espionage Operations | Google Cloud Blog cloud.google.com UNC3886 uses several layers of organized persistence to maintain access to compromised environments over time.
  3. Stealthy cyber spies linked to China compromising virtualization software globally therecord.media A group dubbed 'Fire Ant' is targeting VMware ESXi hypervisors, a type of software that controls and hosts virtual machines for enterprise networks.
  4. Chinese state-backed hacking group compromised US critical infrastructure orgs therecord.media A Chinese state-sponsored hacking group gained access to critical infrastructure organizations in Guam and other parts of the U.S., Microsoft warned on Wednesday.
  5. China’s Salt Typhoon hackers targeting Cisco devices used by telcos, universities therecord.media Researchers discovered compromised Cisco network devices belonging to telecommunications companies in the U.S. and South Africa, as well as others in Italy and Thailand.
  6. Chinese hackers scanning, exploiting Cisco ASA firewalls used by governments worldwide therecord.media In a report shared with Recorded Future News, Unit 42 attributed the targeting of Cisco ASA devices to Storm-1849 — a China-based threat group that Cisco previously said has been attacking the tools since 2024.
  7. Federal agencies not fully patching vulnerable Cisco devices amid ‘active exploitation,’ CISA warns therecord.media Federal civilian agencies are not patching vulnerable Cisco devices sufficiently to protect themselves from an active hacking campaign, the Cybersecurity and Infrastructure Security Agency warned.
  8. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  9. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  10. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  11. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news