Full research report

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

Original reporting โ†—
โ˜… Threat intelligence assessment medium confidence

Executive assessment

The strongest evidence concerns post-compromise activity: concealed GRE tunnelling, router packet capture, selective log forwarding, manipulation of administrative command output and credential interception inside tac_plus. TacTap and BridgeAgent extend previously documented UNC3886-style tradecraft into the authentication and Linux management layers, while REPTILE and MEDUSA provide further behavioural overlap. No evidence identified a Cisco IOS XR vulnerability, affected version range or public exploit, so historical VMware and Fortinet CVEs should not be presented as the cause of this router intrusion. Defenders should treat router configuration and local logs as potentially hostile evidence and corroborate them with protected external telemetry and forensic acquisition.

What happened

On 31 August 2026, reporting described a Sygnia investigation into Fire Ant compromises of Cisco IOS XR routers, TACACS+ servers and associated Linux management hosts. Components reportedly planted during 2025 were reused for hands-on activity in 2026, including traffic capture, credential collection, covert tunnelling and telemetry suppression. The activity overlaps with previously documented UNC3886 tradecraft, but Sygnia did not make a conclusive attribution.

Affected scope

The documented environment included Cisco devices running IOS XR, a tac_plus-based TACACS+ authentication server, a legacy Linux system and other Linux management hosts; affected software versions and the victim organisation were not disclosed. Connected high-value and critical-infrastructure environments reportedly received scans and connection attempts, but their compromise was not confirmed.

Technical assessment

The router implants reportedly modified IOS XR control-plane behaviour to suppress most log messages and conceal an unauthorised Generic Routing Encapsulation tunnel from administrative show-command output. Fire Ant also captured packet data for external transfer, while TacTap injected a library into tac_plus to collect live authentication credentials and BridgeAgent provided persistent command access from a Linux host. This is significant because compromised routing and authentication infrastructure can expose trusted traffic and administrative credentials while simultaneously making configuration and logging evidence unreliable.

Recommended defensive actions

  1. Immediately isolate suspected routers, TACACS+ servers and connected management hosts while preserving volatile memory and network evidence.
  2. Hunt for unexplained Generic Routing Encapsulation interfaces, discrepancies between operational state and commit history, unexpected packet captures and outbound FTP transfers from network devices.
  3. Inspect TACACS+ systems for /usr/sbin/acppid, /lib/libseconfd.so, /var/log/.tacplus.acct, unauthorised library injection and anomalous local Unix sockets involving tac_plus.
  4. Audit Linux hosts for zabbix_agent.service persistence, /opt/.ICEauthority, processes masquerading as /usr/bin/gnome-shell, disabled SELinux and binaries impersonating security products.
  5. Rotate TACACS+, router-administration and other exposed credentials only after restoring the integrity of routing, authentication and management systems.
  6. Restrict router and TACACS+ management access to dedicated administration networks and independently export configuration, authentication and flow telemetry to protected collectors.
  7. Validate device integrity using memory, disk, configuration, authentication and network evidence rather than relying solely on potentially suppressed local logs.

Uncertainties and evidence gaps

  • The method used to obtain initial access to the Cisco IOS XR router is unknown.
  • No affected IOS XR or tac_plus version range, exploited vulnerability or vendor fix was identified.
  • Fire Ant's relationship to UNC3886 is assessed from overlapping targeting and tradecraft rather than conclusive attribution.
  • The victim organisation, campaign scale and number of compromised devices were not disclosed.
  • Scanning and connection attempts towards critical infrastructure were reported, but compromise of those connected environments was not confirmed.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessInitial access to the IOS XR router was not established; the documented activity presupposed privileged control of routing, authentication or management infrastructure.
ComponentCisco IOS XR control-plane libraries and command handling, the tac_plus authentication process, and trusted Linux management hosts.
MechanismPurpose-built components altered logging and command-output behaviour, captured routed traffic, injected credential-collection code into TACACS+ processing and established disguised Linux persistence.
ImpactThe actor could observe trusted traffic, collect administrative credentials, establish covert connectivity and reduce the reliability of logs and administrative inspection.
DetectionLook for unexplained GRE interfaces without corresponding commit history, missing logs or SNMP traps, unexpected packet captures or FTP traffic, TacTap file indicators, zabbix_agent.service anomalies, /opt/.ICEauthority and inconsistencies between live state and independently collected telemetry.
MitigationIsolate and rebuild affected infrastructure from trusted images, remove unauthorised components, rotate exposed credentials, restrict management-plane reachability and export telemetry to protected external collectors; no vulnerability-specific patch was identified.
Exploitation status

Compromise was documented in an investigated intrusion, but no vulnerability-specific active exploitation or public proof-of-concept was identified and initial router access remains unknown.

The investigation began by testing whether the headline described exploitation of a disclosed Cisco vulnerability or a broader infrastructure intrusion. The available reporting supports a real incident involving router, TACACS+ and Linux implants, while earlier Mandiant research independently corroborates closely matching UNC3886 targeting and credential-theft tradecraft. No CVE, public exploit or affected-version range could be tied to the 2026 router compromise, and the inaccessible primary report plus unresolved initial-access path limit the conclusion to medium confidence.

  1. What event and timeline does the supplied story describe?
    Read the complete supplied article and its reported technical details.
    thehackernews.com โ†—

    The article describes components planted in 2025 and reused in 2026 across Cisco IOS XR routers, a TACACS+ server and Linux management hosts, with traffic collection, credential theft and telemetry suppression.

    why This established that the focused event was an observed multi-system intrusion rather than disclosure of a specific Cisco vulnerability.

  2. Could the incident-response firm's primary account be verified directly?
    Opened the linked Sygnia research page.
    sygnia.co โ†—

    The page existed but presented an automated security-verification challenge, preventing direct review of its substantive report content.

    why Because the primary account could not be read directly, detailed incident claims remain dependent on the accessible secondary report and confidence cannot be high.

  3. Does independent research support the proposed UNC3886 overlap and router-focused tradecraft?
    Reviewed Mandiant's investigation of UNC3886 compromises of Juniper routers.
    cloud.google.com โ†—

    Mandiant documented custom router backdoors, disabled logging, long-term persistence and targeting of end-of-life network infrastructure by UNC3886; it also stated that this activity had no identified technical overlap with Salt Typhoon or Volt Typhoon.

    why The findings independently support the behavioural overlap while warning against conflating distinct China-nexus clusters.

  4. Was Fire Ant previously associated with vulnerability exploitation?
    Reviewed the July 2025 reporting on Fire Ant's earlier virtualisation campaign.
    thehackernews.com โ†—

    The earlier reporting associated Fire Ant with exploitation of VMware and other infrastructure vulnerabilities, including CVE-2023-34048 and CVE-2023-20867, before movement into network appliances.

    why Those CVEs provide historical campaign context but are not evidence that the 2026 IOS XR compromise used the same vulnerabilities, so they were excluded from related_cves.

  5. Are TACACS+ credential theft and the named rootkits consistent with established UNC3886 activity?
    Reviewed Mandiant's detailed 2024 UNC3886 intrusion analysis.
    cloud.google.com โ†—

    Mandiant documented UNC3886 extracting TACACS+ credentials with LOOKOVER, replacing tac_plus, and using the REPTILE and MEDUSA rootkits for persistence, evasion and credential collection.

    why This independently corroborates the reported authentication-server focus and malware overlap, but similarity alone does not prove that UNC3886 conducted the Fire Ant intrusion.

ActorsFire AntUNC3886
MalwareTacTapBridgeAgentLOOKOVERREPTILEMEDUSA
TargetsCisco IOS XR routersTACACS+ authentication serversLinux management and jump hostsvirtualisation infrastructurehigh-value and critical-infrastructure networks

Research coverage

All 73 registered source leaves were evaluated for this run: 63 completed, 0 were unavailable, 3 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 62 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 73 sources
SourceRun resultValueWhy it was useful โ€” or not
The Hacker Newsnews ok7 records Primary evidence1 matched items Published the source report used to frame and date the event.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
BleepingComputernews ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CERT-EU Threat Intelligencenews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1687 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5333 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok689 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1013 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok8075 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GitHub topic: pocresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch failed0 records Failed The current collection attempt failed; this source cannot support the report.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok9 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok17 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok5 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1591 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
SentinelLabsnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sophos X-Opsnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
The DFIR Reportnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Unit 42news ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
WeLiveSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Additional verified pages 13 opened outside the registered collection
Analysis & research4
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs thehackernews.com โ†—

Reports the 2025โ€“2026 Cisco IOS XR, TACACS+ and Linux management-host intrusion investigated by Sygnia.

Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers cloud.google.com โ†—

Independently documents UNC3886 targeting routers with custom malware, log suppression and long-term persistence.

Cloaked and Covert: Uncovering UNC3886 Espionage Operations cloud.google.com โ†—

Documents UNC3886 credential theft from TACACS+, use of LOOKOVER, and deployment of REPTILE and MEDUSA.

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments thehackernews.com โ†—

Provides historical context for the earlier Fire Ant activity against virtualisation and network infrastructure.