China-linked Fire Ant attackers hijack Cisco routers
A China-linked hacking group called Fire Ant broke into Cisco IOS XR routers at a target organization and used that access to watch network traffic and quietly connect into other parts of the network.
- Report priority
- High
- Involves
- Cisco IOS XR
What is known
- Sygnia has not published how Fire Ant first got into the routers.
- Once inside, the group used its privileged router access to set up a hidden GRE tunnel, a private data pipe between two points that let it move traffic in and out without it showing up in the router's normal change logs, then used that same access to reach the Linux systems that manage the...
What to do
There is no CVE or specific vulnerable Cisco IOS XR version named in this report, so affected organizations should have their network team check router configurations and TACACS logs against Sygnia's published indicators rather than compare a version number.
Organizations that manage Cisco IOS XR routers or TACACS authentication infrastructure should compare each router's live configuration, including GRE tunnels, against its recorded change history rather than trusting the commit log alone, and review Sygnia's incident report for the TacTap toolset indicators.
Reported details
Investigators reviewing a Cisco IOS XR router notice an active GRE tunnel, a hidden connection carrying traffic between the router and an outside point, that has no matching entry in the router's own change history. That mismatch leads them to find Fire Ant already had privileged access to the router and was using it to monitor traffic passing through. The trail leads further to the organization's TACACS servers, the systems that check admin logins, where Fire Ant had planted its own toolset called TacTap and could harvest admin credentials and login sessions to reach other network devices.
Sygnia attributes this intrusion to Fire Ant, a China-nexus actor it says overlaps with UNC3886 and has previously targeted VMware virtualization environments. In this case the group is reported to have gained privileged access to Cisco IOS XR routers, set up a GRE tunnel that did not appear in the router's commit logs, and pivoted from there into Linux hosts used to manage the routers and into TACACS authentication servers, where it deployed a custom toolset Sygnia calls TacTap. Sygnia says it observed scanning and connection attempts from the compromised infrastructure toward other high-value environments, including systems associated with critical infrastructure, consistent with using trusted network gear as a bridge to a further target.
References
- community.ui.com · fc4a3488-7c43-4628-8bab-f715e96dbfc9 (Security-Advisory-Bulletin-067) patch release notes
- sygnia.co · sygnia-reveals-new-activity-by-china-nexus-threat-actor-fire-ant-targeting-trusted-infrastructure eSecurityPlanet
- bbc.com · c74787w149zo eSecurityPlanet
- thehackernews.com · berlin-refuses-to-pay-hackers-who-stole.html TheHackerNews
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1076 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1096 CERT-FR Advisories
- acn.gov.it · aggiornamenti-di-sicurezza-per-il-linguaggio-di-programmazione-go-4 ACN CSIRT Italy
- acn.gov.it · rilevata-vulnerabilita-in-ruby-1 ACN CSIRT Italy
- acn.gov.it · vulnerabilita-in-prodotti-sonicwall-11 ACN CSIRT Italy
- cyber.gc.ca · ubiquiti-security-advisory-av26-850 CCCS Canada
- cyber.gc.ca · spring-security-advisory-av26-842 CCCS Canada
- spring.io · security CCCS Canada
- cyber.gc.ca · splunk-security-advisory-av26-838 CCCS Canada
- advisory.splunk.com · advisories CCCS Canada
- cyber.gc.ca · nvidia-security-advisory-av26-830 CCCS Canada
- github.com · 5865 (main) CCCS Canada
- nvidia.custhelp.com · 5865 CCCS Canada
- nvidia.custhelp.com · 5817 CCCS Canada
- nvidia.com · security CCCS Canada
- sygnia.co · how-the-safepay-ransomware-group-abused-onedrive-to-steal-data Sygnia
- gbhackers.com · brazilian-financial-firms GBHackers
- infosecurity-magazine.com · tortoiseshell-new-backdoor-ssh Infosecurity Magazine
- infosecurity-magazine.com · reliaquest-not-compromised-by Infosecurity Magazine
- thehackernews.com · meta-ads-push-streamrat-android-trojan.html TheHackerNews
- sonatype.com · hugging-face-security-incident-a-new-class-of-threat-is-here Sonatype
- huggingface.co · security-incident-july-2026 Sonatype
- blog.nns.ee · project-zomboid-vulns NNS Blog
- darkreading.com · threat-gang-springs-vishing-attacks-microsoft-teams-users DarkReading
- thehackernews.com · iranian-hackers-pose-as-recruiters-to.html TheHackerNews
- gbhackers.com · tuktuk-c2-framework GBHackers