[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAeUGyLY-bYx14OkjgO5UL8A6teMtkdKCVef4Gz9Z3IQ":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"d5c12624-fc54-4575-9640-a59bc5e511a6","China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs","china-linked-fire-ant-hijacks-cisco-routers-to-steal-credentials-and-blind-secur-a64532","A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor","A China-nexus cyber espionage actor known as Fire Ant has expanded its campaign to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. The group uses these compromised devices as collection platforms to capture network traffic, harvest credentials, and suppress security logs, potentially gaining access to critical infrastructure. This activity shows an evolution in Fire Ant's tradecraft, including a novel TACACS library-injection technique for credential theft.","China-linked Fire Ant group compromises Cisco routers to steal credentials and blind logs.","China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs Swati KhandelwalAug 31, 2026Cyber Espionage \u002F Network Security A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor turned the compromised routers into collection platforms, capturing network traffic, harvesting credentials, and suppressing the logging and telemetry that defenders rely on to reconstruct an attack. The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments, including critical infrastructure. However, activity against those networks was limited to scanning and connection attempts rather than confirmed compromise. Controlling the routers gave the actor a vantage point over traffic moving through trusted network paths, Sygnia said. \"This activity reinforces one of the core observations from the investigation: when a threat actor controls routers, they do not only gain reach. They gain perspective,\" the firm said. The firm assessed that the activity strongly overlaps with public reporting on UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network edge devices, though it said in its report that it does not make a conclusive attribution. Mandiant, which first documented UNC3886, has said it found no technical overlap between the group and the separate Chinese operations tracked as Salt Typhoon and Volt Typhoon. The 2026 activity follows Sygnia's July 2025 disclosure of Fire Ant, which detailed the group's exploitation of VMware ESXi and vCenter environments before moving into the network and management layers. The investigation began with an anomaly on a Cisco IOS XR router, where a Generic Routing Encapsulation (GRE) tunnel interface was operating with no running configuration or commit history to explain how it had been created. Sygnia did not identify how the actor first gained access to the router. Tracing the tunnel led investigators to a legacy Linux system, from which Fire Ant ran repeated connection attempts and port probing against administrative and service ports on connected networks, including SSH, HTTP, SMB, and RDP. The router malware was purpose-built for the IOS XR control plane rather than a generic Linux appliance. One component embedded a modified system library that checked each outgoing log message for the string Health and forwarded it only when the string was present. A separate component altered the router's command-execution path to append an | exclude filter to show commands, hiding the attacker's tunnel configuration from administrators inspecting the device. Fire Ant then used the routers to capture packet captures (PCAPs) from multiple Cisco devices. The captures were uploaded to external FTP servers, one of which appeared to have been installed the same day the uploads took place. On the TACACS server, Sygnia identified a credential-collection toolset it tracks as TacTap. An injector named acppid loaded a malicious library into the running tac_plus authentication process. The library hooked the functions that accept new connections. It then passed the live session handles to a second process over a local Unix socket. The captured credentials were written to \u002Fvar\u002Flog\u002F.tacplus.acct and lightly obfuscated with a single-byte XOR key of 0xEF. \"To our knowledge, this specific tac_plus library-injection technique has not been publicly described before, making it a notable evolution of Fire Ant's TACACS-focused credential collection tradecraft,\" Sygnia said. Credential theft from TACACS servers is established tradecraft for the cluster, as Mandiant has previously documented UNC3886 deploying a TACACS+ sniffer called LOOKOVER and replacing the tac_plus daemon with a backdoored version to log credentials. Sygnia also recovered a second new tool, a Linux backdoor it called BridgeAgent, which was deployed on the tunnel-connected host and masqueraded as a Zabbix monitoring agent. The implant persisted via a zabbix_agent.service systemd unit running as root, disguised its process as \u002Fusr\u002Fbin\u002Fgnome-shell, and polled the attacker's infrastructure over TLS on port 443 for commands and reverse-shell instructions. Across the Linux management hosts, Fire Ant built a durable access layer using the open-source Medusa and REPTILE rootkits, custom SSH backdoors, and binaries renamed and timestamped to impersonate the SentinelOne and Cybereason endpoint security agents. Several of these components were planted in 2025 and reused for hands-on activity in 2026. At least one backdoor kept running in memory after its file had been deleted from disk, Sygnia said. The actor also worked to undermine the evidence itself by suppressing router logs, SNMP traps, and authentication requests; disabling SELinux on the Linux hosts; rewriting login-history records; and removing entries for privileged commands from system logs. Sygnia said routers, TACACS servers, hypervisors, and jump hosts should be treated as first-class forensic assets, and that investigators should validate logs against memory, disk, network, authentication, and configuration evidence rather than a single telemetry source. Sygnia published the following indicators of compromise (IoCs) - TacTap: the injector \u002Fusr\u002Fsbin\u002Facppid (SHA1 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00), the injected library \u002Flib\u002Flibseconfd.so (955cd45a2f6f226a2fdf44b329af1c8dde90cb38), and the credential file \u002Fvar\u002Flog\u002F.tacplus.acct, decoded with XOR key 0xEF. BridgeAgent: persistence via a zabbix_agent.service systemd unit, encrypted configuration at \u002Fopt\u002F.ICEauthority, and command-and-control (C2) over TLS on port 443. IOS XR implants: \u002Fusr\u002Fbin\u002Facpid (be6b27f429324a4af05a310d8ec9635e37c68a94), \u002Fpkg\u002Fbin\u002Fdhcpd_show_issu_status (1682b652a15bde732489f22809b0b7594c228fd3), \u002Fpkg\u002Fbin\u002Fhd (b149fa3a34bd585e7a674a4fd9538437bd06f514), and the persistence script \u002Fetc\u002Frc.d\u002Finit.d\u002Fgrub-rommon. VMCI backdoor: \u002Fvar\u002Ftmp\u002Faudit (13f0c2a598e3aa63856c032a96b110aed963f0e8), communicating over VMware Virtual Machine Communication Interface (VMCI) sockets. Packet-triggered backdoor: \u002Fvar\u002Ftmp\u002Fping (5ba1242050b5b447052b210788a5a25593d6987d), activating on TCP ports 443, 541, 8443, and 10443 and UDP source port 40443 to destination port 500, triggered by the string sxcdewqaz!@#. The company's full indicator set and YARA rules are available in its report. The activity parallels the router and TACACS+ traffic collection that a CISA-led joint advisory attributed to Salt Typhoon in August 2025, a separate Chinese espionage cluster that captured packet data from compromised routers to harvest administrator credentials across telecommunications networks. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cisco, cyber espionage, linux, Malware, network security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal ","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fchina-linked-fire-ant-hijacks-cisco.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjxYI5Ntk3CPoEGUHNQbd80hij-0QLnz3V_HBU3aXV-mvQq98IE6xsRlbuwZ2PNbbSV7dA-HlNfqRWj0_bd3XpQCOPt9R2gS3PJMm8lfMP_9IoKyhDNbY9NOotNDHO68v2DSUT_R-0UYTqZQc16DJM7OqS8_35iVUMqyy3GrUt7iMaIWz6iW6OSP2ddiDc\u002Fs1600\u002Fcisco-creds.jpg","2026-08-31T09:04:55+00:00","2026-08-31T12:00:10.072256+00:00",9,[18,21,23,25,27,30],{"name":19,"type":20},"Fire Ant","threat_actor",{"name":22,"type":20},"UNC3886",{"name":24,"type":20},"Salt Typhoon",{"name":26,"type":20},"Volt Typhoon",{"name":28,"type":29},"Cisco IOS XR","product",{"name":31,"type":32},"TACACS","technology","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,41,46],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,55],{"type":45,"value":53,"context":54},"TacTap","Credential-collection toolset used on TACACS servers",{"type":45,"value":56,"context":57},"acppid","Injector that loads malicious library into tac_plus process"]