[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fv4JHgFjDKPhIKolYYPqWh4vjzFP8oCrBp2opy1_4_rM":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"0c428365-0840-446b-9443-c1632d966fa5","Chinese Fire Ant hackers turn Cisco routers into spying platforms","chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms-da65f4","The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]","Chinese threat actor Fire Ant has shifted tactics from VMware hypervisors to compromising Cisco IOS XR routers, TACACS servers, and Linux hosts to establish covert surveillance infrastructure. The group deploys custom malware with persistence mechanisms that suppress logging, creates hidden GRE tunnels for traffic capture, and uses compromised routers as vantage points to probe connected high-value networks. Sygnia researchers identified a previously undocumented backdoor called 'BridgeAgent' and attribute the activity to Chinese espionage operations, possibly overlapping with UNC3886.","Chinese Fire Ant threat group compromises Cisco routers to establish surveillance platforms on victim networks.","Chinese Fire Ant hackers turn Cisco routers into spying platforms By Bill Toulas August 31, 2026 10:52 AM 0 The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. According to incident response company Sygnia, the threat actor switched from targeting VMware hypervisors to compromising Cisco routers, TACACS authentication servers, and Linux management hosts. The researchers discovered Fire Ant's new tactic after finding on a Cisco IOS XR router an active GRE (Generic Routing Encapsulation) tunnel interface that could not be explained by a running configuration or commit history. Further analysis revealed that Fire Ant had deployed custom malware on the devices, enabling persistence through a fake system service that ran the implant only during alternating hours. The malware selectively suppressed syslog messages to hide tunnel-related information from legitimate administrators, established outbound Telnet connections to Fire Ant infrastructure, and supported interactive shell access with no logging. Fire Ant's evasion tacticsSource: Sygnia The attackers also used their administrative access to capture traffic from multiple routers and upload the resulting PCAP files to external FTP servers. These captures could expose internal topology, administrative connections, authentication flows, routing relationships, and traffic exchanged with connected networks. “This behavior shifts the router’s role from a transit device to a collection platform,” Sygnia explains. “Once the actor controlled the router, the device became a vantage point for observing traffic moving through trusted network paths.” The concealed GRE tunnel connected one compromised router to a legacy Linux server, which Fire Ant used as a staging and reconnaissance system. From there, the attackers probed systems in connected high-value environments, including systems associated with critical infrastructure, over ports commonly used for SSH, web services, SMB\u002FRPC, and RDP. Sygnia believes that Fire Ant's operation aimed to compromise trusted infrastructure at an initial victim and use it as a covert bridge to explore access paths into connected high-value networks, a tactic which they dub “target behind the target.” Operational overviewSource: Sygnia The researchers also discovered a previously undocumented backdoor called ‘BridgeAgent,’ which Fire Ant disguised as a legitimate Zabbix monitoring agent. The backdoor persists as a root-level systemd service and supports TLS reverse shells and the execution of additional payloads on the compromised host. The GRE tunnel function backing BridgeAgentSource: Sygnia Sygnia says Fire Ant activity strongly overlaps with UNC3886, a Chinese espionage group previously documented by Google. However, the researchers say that there are differences in filenames, paths, and implementation details. The researchers warned that Fire Ant systematically tampers with system logs and records, even changing file timestamps to obscure evidence that would benefit investigators, noting that logs retrieved from compromised infrastructure should be validated against other data. Sygnia's report shares an extensive list of indicators of compromise (IoCs), along with hunting and YARA rules to detect Fire Ant activity. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: New Dysphoria DDoS botnet spreads to 200k devices worldwideUnpatched Calix flaw lets hackers bypass NAT to expose internal devicesFBI disrupts proxy network enabling Chinese espionage operationsUS and allies warn of Russian critical infrastructure attacksHackers exploit Roundcube flaw to spy on academic researchers","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F08\u002F31\u002FFireAnt.jpg","2026-08-31T14:52:03+00:00","2026-08-31T16:00:06.463789+00:00",9,[18,21,23,26,28,31],{"name":19,"type":20},"Fire Ant","threat_actor",{"name":22,"type":20},"UNC3886",{"name":24,"type":25},"Cisco IOS XR","product",{"name":27,"type":25},"Zabbix",{"name":29,"type":30},"Cisco","vendor",{"name":32,"type":30},"Sygnia","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,44,49],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,58,62,65,68,71],{"type":43,"value":56,"context":57},"BridgeAgent","Previously undocumented backdoor disguised as Zabbix monitoring agent, used by Fire Ant for persistence and reverse shell access",{"type":59,"value":60,"context":61},"mitre_attack","T1021.004","SSH exploitation for lateral movement into connected networks",{"type":59,"value":63,"context":64},"T1021.002","SMB\u002FRPC exploitation for lateral movement",{"type":59,"value":66,"context":67},"T1021.001","RDP exploitation for lateral movement",{"type":59,"value":69,"context":70},"T1041","Exfiltration of PCAP traffic captures via FTP to external servers",{"type":59,"value":72,"context":73},"T1562.008","Selective suppression of syslog messages to hide tunnel configuration"]