China-Backed 'Fire Ant' Hackers Exploit Cisco Routers for Covert Espionage
A sophisticated China-based hacking group, dubbed 'Fire Ant' by **Sygnia**, has been observed leveraging **Cisco IOS XR** routers as a stealthy springboard for espionage. The group's evolution from hypervisor compromises to targeting critical network infrastructure highlights a worrying trend where attackers compromise the foundational 'trust layer' of organizations for deep visibility and control.
Cybersecurity firm **Sygnia** has released a detailed report on a highly advanced hacking operation it tracks as "Fire Ant," revealing a string of breaches that underscore the group's sophistication and effectiveness.
According to **Sygnia**, the Fire Ant collective has pivoted from compromising hypervisors to targeting critical network infrastructure, specifically **Cisco IOS XR** routers. These attacks allow the group to monitor organizations, steal credentials, and establish persistent access to high-value environments.
**Asaf Perlman**, director of incident response at **Sygnia**, emphasized the gravity of these attacks: βFire Ant didnβt just compromise systems. It compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure many organizations overlook as legacy technology became the attackerβs vantage point for reach, visibility, and control.β
### Overlap with UNC3886
**Sygnia** researchers note a significant overlap between Fire Ant and **Google Cloud's Mandiant** unit's **UNC3886**, a group implicated in a series of attacks on strategic organizations from 2022 to 2024. Both groups exhibit a similar pattern of taking over infrastructure to collect intelligence and credentials, building durable access, and meticulously concealing their activities.
### Routers: A New Vantage Point
The latest campaign observed by **Sygnia** focuses heavily on **Cisco IOS XR** routers. The attackers developed new tools for persistence and to collect critical credentials, enabling broader access within an organization. They also employed sophisticated anti-forensic techniques, including manipulating firewall rules and deleting logs, to cover their tracks.
"When a threat actor controls routers, they do not only gain reach. They gain perspective," **Sygnia** researchers stated. This allows Fire Ant to observe environments from the inside, gathering intelligence for lateral movement, credential targeting, and cross-network access planning.
### Compromising TACACS Servers
The Fire Ant actors have shown particular adeptness at compromising **TACACS** servers, which act as administrative checkpoints for authenticating users, authorizing commands, and recording activity. By compromising this layer, attackers can harvest credentials in real-time, observe administrative actions, and introduce ambiguity between legitimate and malicious activity.
### A Broader Trend of Chinese Espionage
This activity aligns with a long-standing pattern of Chinese state-backed groups targeting **Cisco** network devices. In 2024, **Volt Typhoon**, a Chinese government espionage unit, was observed targeting end-of-life **Cisco** routers and network devices in the U.S., U.K., and Australia. Similarly, the **Salt Typhoon** campaign in 2023 saw over 1,000 **Cisco** network devices targeted by Chinese actors.
Warnings from **Palo Alto Networksβ Unit 42** and federal cyber defense agencies between September and December 2025 also highlighted attacks by China-based hackers on **Cisco Adaptive Security Appliances (ASA)**, popular devices used by governments and large businesses.
### The Need for Enhanced Infrastructure Security
**Andrew Obadiaru**, vice president at **Cobalt**, highlighted the attackers' focus on staying invisible within infrastructure that defenders rarely monitor closely. These devices, often outside the purview of traditional security tools, become attractive targets because they typically do not trigger alerts.
βThis pattern of long-dwell, infrastructure-level access lines up with what we've seen from other Chinese espionage clusters targeting telecom and network infrastructure, and it argues for continuous validation of trust relationships across management infrastructure rather than periodic checks,β Obadiaru commented.
**Sygnia**'s report serves as a critical reminder that routers, hypervisors, and other core infrastructure components must be treated as "first-class" security assets, demanding rigorous monitoring, hardening, and incident response readiness.