Fire Ant Espionage Campaign Expands to Cisco Routers and Network Infrastructure

Sygnia reported that the China-nexus actor tracked as Fire Ant has broadened a long-running espionage operation beyond VMware environments to target Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts used to route, authenticate, and manage high-value networks. The incident response firm discovered an unexplained Generic Routing Encapsulation tunnel on a Cisco IOS XR router, indicating that attackers used compromised routers to collect network traffic, harvest administrative credentials, and suppress logging and telemetry. While the activity strongly overlaps with public reporting on UNC3886, a known China-nexus group targeting virtualization and network edge devices, Sygnia did not make conclusive attribution; in connected high-value environments, including critical infrastructure, only scanning and connection attempts (rather than confirmed compromise) were observed. The custom malware deployed by Fire Ant persisted through a fake system service and ran only during alternating hours to evade detection.

The Router That Became a Wiretap

You have to understand what they've done here. This isn't some run-of-the-mill hack where someone steals a password database. Fire Ant — and let's be clear, these are state-sponsored operators whose tasking comes from a level far above any individual agency — took control of the spines of the network themselves. They found the Cisco IOS XR routers, the very devices that make the internet work for high-value networks. And what did they do? They created a hidden tunnel, a ghost in the machine that existed nowhere in the configuration history. Think about the technical sophistication required to do that. The administrators looked at their own hardware and couldn't explain how it was happening. That's not a script kiddie with a stolen exploit. That is someone who has the same knowledge as the engineers who built the equipment, who knows the gaps in Cisco's own logging and management systems.

The Suppression of the Crime

And then there's the most chilling detail in the entire report: "suppress logging and telemetry used by defenders." You see? They didn't just steal data. They made sure the data theft itself was invisible. They tampered with the very systems that are supposed to tell you something is wrong. This is the hallmark of a group that has been doing this for years, not months. Fire Ant knows exactly what a Security Operations Center looks at, what triggers an alert, and how to turn those off before they turn on the tap. TACACS authentication servers — that's the master key system for who gets into the network. They compromised that too. They are harvesting credentials, and with those credentials, they don't have to hack in again. They can walk in the front door, because now they have the keys.

The Managed Narrative of Attribution

Now, watch the language closely. Sygnia says the activity "strongly overlaps" with UNC3886, but they didn't make a "conclusive attribution." Why not? Ask yourself that. This company, Sygnia, found a live, active intrusion on some of the most sensitive infrastructure imaginable. They have the forensic evidence, the implants, the custom malware that persists through fake system services. They can see the attack surface. And yet they stop short of naming the ultimate master of this operation. The pressure not to assign full attribution to a specific state actor is immense, because the moment you do, you trigger a geopolitical incident. This is the architecture of consent in action. The technical reality is that you have a group operating on Chinese government timelines, targeting the brains of the infrastructure, and the public gets told it's just an "espionage campaign." Read the documents people. The scanning and connection attempts on critical infrastructure are not reconnaissance. They are site surveys. They are marking the targets.