Full research report
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Executive assessment
The strongest evidence concerns post-compromise activity: concealed GRE tunnelling, router packet capture, selective log forwarding, manipulation of administrative command output and credential interception inside tac_plus. TacTap and BridgeAgent extend previously documented UNC3886-style tradecraft into the authentication and Linux management layers, while REPTILE and MEDUSA provide further behavioural overlap. No evidence identified a Cisco IOS XR vulnerability, affected version range or public exploit, so historical VMware and Fortinet CVEs should not be presented as the cause of this router intrusion. Defenders should treat router configuration and local logs as potentially hostile evidence and corroborate them with protected external telemetry and forensic acquisition.
What happened
On 31 August 2026, reporting described a Sygnia investigation into Fire Ant compromises of Cisco IOS XR routers, TACACS+ servers and associated Linux management hosts. Components reportedly planted during 2025 were reused for hands-on activity in 2026, including traffic capture, credential collection, covert tunnelling and telemetry suppression. The activity overlaps with previously documented UNC3886 tradecraft, but Sygnia did not make a conclusive attribution.
Affected scope
The documented environment included Cisco devices running IOS XR, a tac_plus-based TACACS+ authentication server, a legacy Linux system and other Linux management hosts; affected software versions and the victim organisation were not disclosed. Connected high-value and critical-infrastructure environments reportedly received scans and connection attempts, but their compromise was not confirmed.
Technical assessment
The router implants reportedly modified IOS XR control-plane behaviour to suppress most log messages and conceal an unauthorised Generic Routing Encapsulation tunnel from administrative show-command output. Fire Ant also captured packet data for external transfer, while TacTap injected a library into tac_plus to collect live authentication credentials and BridgeAgent provided persistent command access from a Linux host. This is significant because compromised routing and authentication infrastructure can expose trusted traffic and administrative credentials while simultaneously making configuration and logging evidence unreliable.
Recommended defensive actions
- Immediately isolate suspected routers, TACACS+ servers and connected management hosts while preserving volatile memory and network evidence.
- Hunt for unexplained Generic Routing Encapsulation interfaces, discrepancies between operational state and commit history, unexpected packet captures and outbound FTP transfers from network devices.
- Inspect TACACS+ systems for /usr/sbin/acppid, /lib/libseconfd.so, /var/log/.tacplus.acct, unauthorised library injection and anomalous local Unix sockets involving tac_plus.
- Audit Linux hosts for zabbix_agent.service persistence, /opt/.ICEauthority, processes masquerading as /usr/bin/gnome-shell, disabled SELinux and binaries impersonating security products.
- Rotate TACACS+, router-administration and other exposed credentials only after restoring the integrity of routing, authentication and management systems.
- Restrict router and TACACS+ management access to dedicated administration networks and independently export configuration, authentication and flow telemetry to protected collectors.
- Validate device integrity using memory, disk, configuration, authentication and network evidence rather than relying solely on potentially suppressed local logs.
Uncertainties and evidence gaps
- The method used to obtain initial access to the Cisco IOS XR router is unknown.
- No affected IOS XR or tac_plus version range, exploited vulnerability or vendor fix was identified.
- Fire Ant's relationship to UNC3886 is assessed from overlapping targeting and tradecraft rather than conclusive attribution.
- The victim organisation, campaign scale and number of compromised devices were not disclosed.
- Scanning and connection attempts towards critical infrastructure were reported, but compromise of those connected environments was not confirmed.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
Compromise was documented in an investigated intrusion, but no vulnerability-specific active exploitation or public proof-of-concept was identified and initial router access remains unknown.
The investigation began by testing whether the headline described exploitation of a disclosed Cisco vulnerability or a broader infrastructure intrusion. The available reporting supports a real incident involving router, TACACS+ and Linux implants, while earlier Mandiant research independently corroborates closely matching UNC3886 targeting and credential-theft tradecraft. No CVE, public exploit or affected-version range could be tied to the 2026 router compromise, and the inaccessible primary report plus unresolved initial-access path limit the conclusion to medium confidence.
- What event and timeline does the supplied story describe?Read the complete supplied article and its reported technical details.thehackernews.com โ
The article describes components planted in 2025 and reused in 2026 across Cisco IOS XR routers, a TACACS+ server and Linux management hosts, with traffic collection, credential theft and telemetry suppression.
why This established that the focused event was an observed multi-system intrusion rather than disclosure of a specific Cisco vulnerability.
- Could the incident-response firm's primary account be verified directly?Opened the linked Sygnia research page.sygnia.co โ
The page existed but presented an automated security-verification challenge, preventing direct review of its substantive report content.
why Because the primary account could not be read directly, detailed incident claims remain dependent on the accessible secondary report and confidence cannot be high.
- Does independent research support the proposed UNC3886 overlap and router-focused tradecraft?Reviewed Mandiant's investigation of UNC3886 compromises of Juniper routers.cloud.google.com โ
Mandiant documented custom router backdoors, disabled logging, long-term persistence and targeting of end-of-life network infrastructure by UNC3886; it also stated that this activity had no identified technical overlap with Salt Typhoon or Volt Typhoon.
why The findings independently support the behavioural overlap while warning against conflating distinct China-nexus clusters.
- Was Fire Ant previously associated with vulnerability exploitation?Reviewed the July 2025 reporting on Fire Ant's earlier virtualisation campaign.thehackernews.com โ
The earlier reporting associated Fire Ant with exploitation of VMware and other infrastructure vulnerabilities, including CVE-2023-34048 and CVE-2023-20867, before movement into network appliances.
why Those CVEs provide historical campaign context but are not evidence that the 2026 IOS XR compromise used the same vulnerabilities, so they were excluded from related_cves.
- Are TACACS+ credential theft and the named rootkits consistent with established UNC3886 activity?Reviewed Mandiant's detailed 2024 UNC3886 intrusion analysis.cloud.google.com โ
Mandiant documented UNC3886 extracting TACACS+ credentials with LOOKOVER, replacing tac_plus, and using the REPTILE and MEDUSA rootkits for persistence, evasion and credential collection.
why This independently corroborates the reported authentication-server focus and malware overlap, but similarity alone does not prove that UNC3886 conducted the Fire Ant intrusion.
Research coverage
All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 62 completed sources contained no matched information for this story.
Complete source-by-source audit 73 sources
| Source | Run result | Value | Why it was useful โ or not |
|---|---|---|---|
| The Hacker Newsnews | ok7 records | Primary evidence1 matched items | Published the source report used to frame and date the event. |
| AlienVault OTXdark_web | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| BleepingComputernews | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| CERT-EU Threat Intelligencenews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| CIRCL CVEcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| CISA Alertsnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| CISA KEVkev | ok1687 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5333 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok689 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1013 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| FIRST EPSSepss | ok8075 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| GitHub topic: pocresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| GreyNoiseexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok9 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok17 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok19 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok5 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok19 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1591 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok3 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| MISP threat actor galaxyactor | ok0 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| NVDcve | ok900 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| SentinelLabsnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sigma Rulesresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sophos X-Opsnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| The DFIR Reportnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| ThreatFoxthreat_intelligence | ok100 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Unit 42news | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Unit42 IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| WeLiveSecuritynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
Additional verified pages 13 opened outside the registered collection
Analysis & research4
Reports the 2025โ2026 Cisco IOS XR, TACACS+ and Linux management-host intrusion investigated by Sygnia.
Independently documents UNC3886 targeting routers with custom malware, log suppression and long-term persistence.
Documents UNC3886 credential theft from TACACS+, use of LOOKOVER, and deployment of REPTILE and MEDUSA.
Provides historical context for the earlier Fire Ant activity against virtualisation and network infrastructure.