Sygnia has a report on Fire Ant, the China-linked group that has expanded from VMware hypervisor attacks to compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, I
First reported in 2025, Fire Ant remained active into 2026. Explore how the threat actor expanded beyond hypervisors into trusted infrastructure, compromising routers, authentication systems, and Linux management hosts to maintain covert access, collect credentials and traffic, and reach connected high-value environments.
Justin Beals, CEO & Founder of Strike Graph
“This is the same playbook we saw with Salt Typhoon. When an actor controls the routers, they do not just gain access. They gain perspective on everything moving through that network. TACACS servers are especially dangerous to lose because they are the authentication backbone. Once an attacker owns that layer, they are not breaking in anymore. They are logging in.
The part that should worry every security leader is the log suppression. Fire Ant did not just steal credentials. It edited what defenders could see. That is a direct attack on your ability to trust your own evidence. If you cannot verify your logs, you cannot verify your incident response.
Organizations need to start treating routers and TACACS servers as first class assets in their security program, not just plumbing. That means continuous validation of configuration and log integrity, not a once a year review. Nation-state actors are patient. They will sit in network infrastructure for over a year before using it. The only defense is verifying your environment constantly, not periodically.”
Andrew Obadiaru, VP and CISO at Cobalt
“What stands out here isn’t the initial access, it’s how much effort Fire Ant put into staying invisible on infrastructure defenders rarely instrument closely. TACACS servers, hypervisors, and jump hosts tend to sit outside normal EDR coverage, which makes them attractive precisely because compromise there doesn’t trigger the alerts a workstation infection would. Injecting a credential-harvesting library directly into a running authentication process, rather than dropping a standalone sniffer, is a meaningful evolution because it blends into legitimate process behavior and survives more routine cleanup. Renaming backdoors to impersonate SentinelOne and Cybereason processes reflects the same logic: attackers are increasingly optimizing for what an analyst glances past rather than what a signature catches. The evidence tampering here, rewriting login history, suppressing SNMP and router logs, disabling SELinux, is also a reminder that single-source telemetry can’t be trusted for high-value infrastructure. Organizations should treat routers, TACACS servers, and hypervisors as first-class forensic assets, not just plumbing, and validate authentication logs against memory, disk, and network evidence independently. This pattern of long-dwell, infrastructure-level access lines up with what we’ve seen from other Chinese espionage clusters targeting telecom and network infrastructure, and it argues for continuous validation of trust relationships across management infrastructure rather than periodic checks.”
This is a good segue into having me say that you need to check your routers among other things ASAP to make sure that this group, or any other group hasn’t infiltrated your network.
Related
This entry was posted on August 31, 2026 at 2:46 pm and is filed under Commentary with tags Sygnia. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Chinese Espionage Group Turns Routers Into Surveillance Platforms
Sygnia has a report on Fire Ant, the China-linked group that has expanded from VMware hypervisor attacks to compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, I
First reported in 2025, Fire Ant remained active into 2026. Explore how the threat actor expanded beyond hypervisors into trusted infrastructure, compromising routers, authentication systems, and Linux management hosts to maintain covert access, collect credentials and traffic, and reach connected high-value environments.
Justin Beals, CEO & Founder of Strike Graph
“This is the same playbook we saw with Salt Typhoon. When an actor controls the routers, they do not just gain access. They gain perspective on everything moving through that network. TACACS servers are especially dangerous to lose because they are the authentication backbone. Once an attacker owns that layer, they are not breaking in anymore. They are logging in.
The part that should worry every security leader is the log suppression. Fire Ant did not just steal credentials. It edited what defenders could see. That is a direct attack on your ability to trust your own evidence. If you cannot verify your logs, you cannot verify your incident response.
Organizations need to start treating routers and TACACS servers as first class assets in their security program, not just plumbing. That means continuous validation of configuration and log integrity, not a once a year review. Nation-state actors are patient. They will sit in network infrastructure for over a year before using it. The only defense is verifying your environment constantly, not periodically.”
Andrew Obadiaru, VP and CISO at Cobalt
“What stands out here isn’t the initial access, it’s how much effort Fire Ant put into staying invisible on infrastructure defenders rarely instrument closely. TACACS servers, hypervisors, and jump hosts tend to sit outside normal EDR coverage, which makes them attractive precisely because compromise there doesn’t trigger the alerts a workstation infection would. Injecting a credential-harvesting library directly into a running authentication process, rather than dropping a standalone sniffer, is a meaningful evolution because it blends into legitimate process behavior and survives more routine cleanup. Renaming backdoors to impersonate SentinelOne and Cybereason processes reflects the same logic: attackers are increasingly optimizing for what an analyst glances past rather than what a signature catches. The evidence tampering here, rewriting login history, suppressing SNMP and router logs, disabling SELinux, is also a reminder that single-source telemetry can’t be trusted for high-value infrastructure. Organizations should treat routers, TACACS servers, and hypervisors as first-class forensic assets, not just plumbing, and validate authentication logs against memory, disk, and network evidence independently. This pattern of long-dwell, infrastructure-level access lines up with what we’ve seen from other Chinese espionage clusters targeting telecom and network infrastructure, and it argues for continuous validation of trust relationships across management infrastructure rather than periodic checks.”
This is a good segue into having me say that you need to check your routers among other things ASAP to make sure that this group, or any other group hasn’t infiltrated your network.
Share this:
Like this:
Related
This entry was posted on August 31, 2026 at 2:46 pm and is filed under Commentary with tags Sygnia. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.