China-Nexus Fire Ant Hackers Target Cisco Routers, TACACS Servers for Espionage

China-Nexus Fire Ant Hackers Target Cisco Routers, TACACS Servers for Espionage

Sygnia details Fire Ant attacks on Cisco routers, TACACS servers and Linux hosts used to steal credentials, collect traffic data and conceal malicious activity.

Listen to this article

0:00

Press play to start listening

A cyber espionage group has expanded its operations beyond VMware virtualization infrastructure to target trusted network and management systems. Tracked by cybersecurity firm Sygnia as Fire Ant, the group has targeted Cisco IOS XR routers, Linux management hosts and TACACS servers, which handle administrative authentication flows.

In an August 30 press release accompanying technical research dated August 27, Sygnia said its investigation found long-running activity against infrastructure used to route traffic, authenticate administrators and manage connected environments.

Sygnia first reported Fire Ant in 2025 after identifying activity targeting VMware ESXi and vCenter environments. The latest investigation shows the group expanding beyond those virtualization systems to infrastructure that connects and manages wider networks. These systems occupy central positions in an organisation’s network, giving attackers visibility into traffic, access to administrative credentials and routes into connected systems. explore further access.

New Tools for Access and Credential Theft

Sygnia identified two previously undocumented tools. One, called BridgeAgent, masqueraded as a Zabbix monitoring agent on Linux systems. It persisted through a zabbix_agent.service systemd unit running with root privileges, periodically retrieved configuration through HTTPS and supported outbound TLS reverse-shell connections to attacker-controlled infrastructure over port 443.

The second toolset, tracked as TacTap, targeted TACACS authentication infrastructure. An injector loaded a malicious library into the running tac_plus authentication process, allowing Fire Ant to intercept accepted TACACS sessions. The resulting credential material was written to /var/log/.tacplus.acct and obfuscated using the single-byte XOR key 0xEF.

The attackers also turned compromised Cisco routers into operational platforms for covert connectivity and traffic collection. Investigators identified a suspicious Generic Routing Encapsulation (GRE) tunnel and found that Fire Ant had captured packet data from multiple Cisco devices. The malware also altered router command output to conceal the tunnel configuration from administrators.

Compromised environment (Credit: Sygnia)

Covering Tracks Across Network Systems

Fire Ant built a durable access layer across Linux management hosts using Medusa rootkit-related components, custom SSH backdoors, Zabbix-masquerading malware and packet-triggered backdoors. Some of these components were planted in 2025 and reused during 2026 activity.

The group also manipulated the evidence defenders rely on. It suppressed router logging, SNMP traps and authentication-related telemetry while filtering command output. On Linux hosts, attackers disabled SELinux, tampered with logs and login histories, modified firewall rules and deleted files after execution. At least one backdoor continued running in memory after its file had been removed from disk.

Sygnia said Fire Ant’s activity strongly overlaps with public reporting on the China-linked espionage cluster UNC3886, although it did not make a conclusive attribution. The firm recommends treating routers, TACACS servers, hypervisors and management hosts as first-class forensic assets and validating logs against memory, disk, network, authentication and configuration evidence.

Deployment process and defence-evasion techniques (Credit: Sygnia)

Experts Assess the Threat

The findings were also reviewed by cybersecurity experts who shared comments with Hackread.com. Justin Beals, CEO and Founder of Strike Graph, said the activity resembles the playbook seen with Salt Typhoon and explained why control of network infrastructure is particularly valuable to attackers:

“When an actor controls the routers, they do not just gain access. They gain perspective on everything moving through that network. TACACS servers are especially dangerous to lose because they are the authentication backbone. Once an attacker owns that layer, they are not breaking in anymore. They are logging in.”

Beals also highlighted the attackers’ manipulation of logs and other evidence:

“The part that should worry every security leader is the log suppression. Fire Ant did not just steal credentials. It edited what defenders could see. That is a direct attack on your ability to trust your own evidence.”

Andrew Obadiaru, CISO at Cobalt, focused on the effort to remain hidden on infrastructure that may receive less monitoring than conventional endpoints:

“What stands out here isn’t the initial access, it’s how much effort Fire Ant put into staying invisible on infrastructure defenders rarely instrument closely.”

Obadiaru also pointed to the credential-theft technique and evidence manipulation, saying:

“Injecting a credential-harvesting library directly into a running authentication process, rather than dropping a standalone sniffer, is a meaningful evolution because it blends into legitimate process behavior and survives more routine cleanup.”

He added that “single-source telemetry can’t be trusted for high-value infrastructure” and recommended treating routers, TACACS servers and hypervisors as first-class forensic assets.

(Photo by Chris Yang on Unsplash)

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts