Zero Day Room
Live
Vulnerabilities

Fire Ant Hackers Breach Cisco Routers

The China-linked Fire Ant group compromised Cisco IOS XR routers to steal credentials, monitor networks, and launch further attacks,

The China-linked Fire Ant group compromised Cisco IOS XR routers to steal credentials, monitor networks, and launch...

A China-based hacking group compromised Cisco routers. They stole credentials, monitored organizations, and launched attacks on other networks. Cybersecurity firm Sygnia detailed the campaign, which it calls "Fire Ant," in a new report.

Sygnia said Fire Ant overlaps with a group tracked by Google Cloud's Mandiant unit as UNC3886. This group was implicated in attacks on strategic organizations from 2022 to 2024. The Israel-based company warned that the actors have evolved. They now focus on the infrastructure that connects environments. This includes routers, hypervisors, and Linux management hosts.

Campaign Targets Cisco Routers

The latest tracked activity focuses on attacks against Cisco IOS XR routers. Sygnia uncovered new tools the group used for persistence and credential collection. These tools enabled wider access within victim organizations.

The attackers also hid logs and manipulated evidence. They often deleted files and tampered with firewall rules. After Sygnia reported on Fire Ant in 2025, the group remained active in 2026. The 2026 compromises impacted both primary victims and third-party environments. The hackers exploited infrastructure relationships to breach high-value networks and critical infrastructure. Sygnia did not name the specific organizations impacted.

Gaining Perspective and Control

The malware used was built specifically to control routers and modify them for the hackers' needs. Fire Ant actors captured traffic from multiple Cisco routers and uploaded data to external infrastructure. They sought network vantage points from across the environment. This gave them a broad view of how systems, administrators, and connected networks interacted.

This activity reinforces one of the core observations from the investigation. When a threat actor controls routers, they do not only gain reach.

The group became adept at compromising TACACS servers, which act as administrative checkpoints. Compromising this layer let the threat actors harvest credentials as they were used. They could observe administrative activity. They could also create ambiguity between legitimate and malicious actions.

Asaf Perlman, director of incident response at Sygnia, emphasized the campaign's significance. Fire Ant didn't just compromise systems. It compromised the trust layer those systems depend on.

A Pattern of Infrastructure Targeting

Sygnia warned that routers and hypervisors must be treated as "first-class" security assets. They require monitoring and hardening. Governments and cybersecurity companies have long warned that Chinese state-backed groups target Cisco firewalls and routers.

In 2024, the Chinese espionage unit Volt Typhoon was seen targeting end-of-life Cisco routers in the U.S., U.K., and Australia. Last year, defenders said more than 1,000 Cisco network devices were targeted by Chinese actors as part of the Salt Typhoon campaign.

Between September and December 2025, Palo Alto Networks' Unit 42 and a federal cyber defense agency repeatedly warned that China-based hackers were attacking Cisco Adaptive Security Appliances (ASA).

Several experts said Sygnia's findings were instructive. Andrew Obadiaru, vice president at Cobalt, said the effort Fire Ant put into staying invisible on rarely watched infrastructure stood out. The targeted devices are typically outside the coverage of security tools. They do not trigger alerts.

This pattern of long-dwell, infrastructure-level access lines up with what we've seen from other Chinese espionage clusters targeting telecom and network infrastructure. He argued for continuous validation of trust relationships across management infrastructure.

Topics

#Cisco

Related coverage

More from Vulnerabilities