China-linked hackers turn Cisco routers into covert attack infrastructure
BreachA China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia. The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR routers in 2026, using them to collect network traffic while suppressing evidence of its activity. The attackers also compromised TACACS authentication infrastructure and Linux management hosts as they explored access to connected high-value environments. The findings build on Sygnia research published last year that documented Fire Ant establishing deep persistence in VMware ESXi and vCenter environments. The latest activity shows the group extending that approach into infrastructure used to route traffic and administer enterprise networks. Sygnia found attempts to suppress logging and conceal configuration activity on affected network equipment, while evidence was also tampered with on compromised Linux systems. The firm described the operation as creating a potential “target behind the target” scenario, in which access to one organization’s trusted infrastructure could expose paths toward other high-value environments. Sygnia said Fire Ant probed systems associated with critical infrastructure, although the report does not establish that the critical-infrastructure systems being probed were successfully compromised. Sygnia assesses that Fire Ant’s activity strongly overlaps with publicly reported operations attributed to UNC3886, a China-nexus espionage cluster tracked by Mandiant, but has not treated the two as definitively identical. Mandiant has previously documented UNC3886 targeting network equipment and TACACS infrastructure while attempting to evade conventional monitoring. When telemetry becomes the target The Fire Ant campaign raises a difficult question for defenders: whether they can trust the systems producing the evidence used to investigate an attack. “If the system generating the evidence has itself been compromised, the absence of an alert or log entry can no longer be treated as proof that an action did not occur,” said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services. The suppression of AAA requests, SNMP traps and command output could leave gaps around administrator activity, configuration changes, and credential use. Grover said enterprises should avoid relying on a single device or management plane as the authoritative source of evidence. Critical telemetry should be exported to separately administered systems and checked against independent sources such as identity platforms and network-flow data. An unexplained loss of telemetry, or disagreement between different evidence sources, can itself become a useful detection signal. Infrastructure in the security spotlight Fire Ant also adds to evidence that sophisticated espionage groups are looking beyond conventional endpoints toward systems that occupy privileged positions inside enterprise networks. Grover cautioned that one campaign does not establish an industry-wide shift, but said it fits a broader pattern among sophisticated China-linked actors of targeting highly privileged infrastructure that may receive less consistent monitoring. Akshat Tyagi, associate practice leader at HFS Research, said network infrastructure remains a blind spot because security teams have traditionally monitored endpoints and servers more closely than the systems connecting and administering them. Control of network infrastructure can give attackers visibility into traffic and potential routes into systems connected through trusted links. What CISOs should change For CISOs, the campaign is another reason to apply the same level of security scrutiny to network and authentication infrastructure as they do to endpoints and servers. Grover said TACACS and similar authentication systems should be treated as Tier-0 assets because compromising them can expose privileged credentials while weakening administrative audit trails. Neil Shah, vice president for research at Counterpoint Research, said the same Zero Trust principles applied elsewhere in the enterprise should extend to this Tier-0 infrastructure, with organizations continuously checking its integrity rather than assuming trusted systems remain trustworthy. “Zero Trust now has to span from software to hardware,” Shah said. That means hardening privileged authentication paths and applying tighter controls to administrative traffic and the software allowed to run on critical infrastructure. Tyagi said CISOs should also focus on containing what he described as the “blast radius of trust,” limiting how far an attacker can move if a trusted system or connection is compromised. That requires examining network links according to what they make reachable and separating sensitive environments where possible, rather than assuming a trusted connection is inherently safe. Incident-response plans should assume routers or authentication servers themselves may be compromised. Organizations therefore need independently retained evidence and out-of-band access so that responders are not forced to rely on the same management infrastructure they are investigating.
Read full story at CSO Online →