China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Logs

This digest was compiled by AI from multiple sources — links to the originals are below.
A China-nexus cyber espionage actor tracked as Fire Ant has expanded its campaign to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. Sygnia, the incident response firm that investigated the intrusion, said the actor used the routers to capture traffic, harvest credentials, and suppress logging. The activity strongly overlaps with public reporting on UNC3886, though Sygnia did not make a conclusive attribution.
Key Facts
- Fire Ant compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts, according to Sygnia.
- The actor used compromised routers to capture packet captures from multiple Cisco devices.
- Sygnia assessed that the activity strongly overlaps with public reporting on UNC3886, a China-nexus espionage group.
- The investigation began with an anomaly on a Cisco IOS XR router where a GRE tunnel interface had no running configuration or commit history.
- Fire Ant ran repeated connection attempts and port probing against SSH, HTTP, SMB, and RDP ports from a legacy Linux system.
Campaign Expansion
Fire Ant expanded its long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. Sygnia said the actor turned the compromised routers into collection platforms, capturing network traffic, harvesting credentials, and suppressing logging and telemetry. The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments, including critical infrastructure. Activity against those networks was limited to scanning and connection attempts rather than confirmed compromise.
Router Malware Techniques
The router malware was purpose-built for the IOS XR control plane rather than a generic Linux appliance. One component embedded a modified system library that checked each outgoing log message for the string Health and forwarded it only when the string was present. A separate component altered the router's command-execution path to append an | exclude filter to show commands, hiding the attacker's tunnel configuration from administrators. Fire Ant then used the routers to capture packet captures from multiple Cisco devices.
Attribution and Overlap
Sygnia assessed that the activity strongly overlaps with public reporting on UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network edge devices. The firm said in its report that it does not make a conclusive attribution. Mandiant, which first documented UNC3886, has said it found no technical overlap between the group and the separate Chinese operations tracked as Salt Typhoon and Volt Typhoon.