Close Menu
NCIJ Network NCIJ Network
    What's Hot

    This Marine Died in the Iraq War. His Mother Asks, ‘What Was It For?’

    August 31, 2026

    Banks and insurers brace for biggest German pension upheaval in 20 years

    August 31, 2026

    Why Food Keeps Making Everybody Sick This Summer

    August 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This Marine Died in the Iraq War. His Mother Asks, ‘What Was It For?’
    • Banks and insurers brace for biggest German pension upheaval in 20 years
    • Why Food Keeps Making Everybody Sick This Summer
    • China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
    • XRP Ledger study finds random peer links raise resilience
    • Some signs of quantum gravity may be an illusion
    • Recording a rainforest before Indonesia’s new capital changes it
    • Etu Energias strikes $260 million deal with Chevron for Angola’s deepwater block duo
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 31, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.

    Sygnia, the incident response firm that investigated the intrusion, said the actor turned the compromised routers into collection platforms, capturing network traffic, harvesting credentials, and suppressing the logging and telemetry that defenders rely on to reconstruct an attack.

    The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments, including critical infrastructure. However, activity against those networks was limited to scanning and connection attempts rather than confirmed compromise.

    Controlling the routers gave the actor a vantage point over traffic moving through trusted network paths, Sygnia said.

    “This activity reinforces one of the core observations from the investigation: when a threat actor controls routers, they do not only gain reach. They gain perspective,” the firm said.

    The firm assessed that the activity strongly overlaps with public reporting on UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network edge devices, though it said in its report that it does not make a conclusive attribution.

    Cybersecurity

    Mandiant, which first documented UNC3886, has said it found no technical overlap between the group and the separate Chinese operations tracked as Salt Typhoon and Volt Typhoon.

    The 2026 activity follows Sygnia’s July 2025 disclosure of Fire Ant, which detailed the group’s exploitation of VMware ESXi and vCenter environments before moving into the network and management layers.

    The investigation began with an anomaly on a Cisco IOS XR router, where a Generic Routing Encapsulation (GRE) tunnel interface was operating with no running configuration or commit history to explain how it had been created. Sygnia did not identify how the actor first gained access to the router.

    Tracing the tunnel led investigators to a legacy Linux system, from which Fire Ant ran repeated connection attempts and port probing against administrative and service ports on connected networks, including SSH, HTTP, SMB, and RDP.

    The router malware was purpose-built for the IOS XR control plane rather than a generic Linux appliance. One component embedded a modified system library that checked each outgoing log message for the string Health and forwarded it only when the string was present.

    A separate component altered the router’s command-execution path to append an | exclude filter to show commands, hiding the attacker’s tunnel configuration from administrators inspecting the device.

    Fire Ant then used the routers to capture packet captures (PCAPs) from multiple Cisco devices. The captures were uploaded to external FTP servers, one of which appeared to have been installed the same day the uploads took place.

    On the TACACS server, Sygnia identified a credential-collection toolset it tracks as TacTap.

    An injector named acppid loaded a malicious library into the running tac_plus authentication process. The library hooked the functions that accept new connections. It then passed the live session handles to a second process over a local Unix socket.

    The captured credentials were written to /var/log/.tacplus.acct and lightly obfuscated with a single-byte XOR key of 0xEF.

    “To our knowledge, this specific tac_plus library-injection technique has not been publicly described before, making it a notable evolution of Fire Ant’s TACACS-focused credential collection tradecraft,” Sygnia said.

    Credential theft from TACACS servers is established tradecraft for the cluster, as Mandiant has previously documented UNC3886 deploying a TACACS+ sniffer called LOOKOVER and replacing the tac_plus daemon with a backdoored version to log credentials.

    Sygnia also recovered a second new tool, a Linux backdoor it called BridgeAgent, which was deployed on the tunnel-connected host and masqueraded as a Zabbix monitoring agent.

    The implant persisted via a zabbix_agent.service systemd unit running as root, disguised its process as /usr/bin/gnome-shell, and polled the attacker’s infrastructure over TLS on port 443 for commands and reverse-shell instructions.

    Across the Linux management hosts, Fire Ant built a durable access layer using the open-source Medusa and REPTILE rootkits, custom SSH backdoors, and binaries renamed and timestamped to impersonate the SentinelOne and Cybereason endpoint security agents.

    Several of these components were planted in 2025 and reused for hands-on activity in 2026. At least one backdoor kept running in memory after its file had been deleted from disk, Sygnia said.

    The actor also worked to undermine the evidence itself by suppressing router logs, SNMP traps, and authentication requests; disabling SELinux on the Linux hosts; rewriting login-history records; and removing entries for privileged commands from system logs.

    Cybersecurity

    Sygnia said routers, TACACS servers, hypervisors, and jump hosts should be treated as first-class forensic assets, and that investigators should validate logs against memory, disk, network, authentication, and configuration evidence rather than a single telemetry source.

    Sygnia published the following indicators of compromise (IoCs) –

    • TacTap: the injector /usr/sbin/acppid (SHA1 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00), the injected library /lib/libseconfd.so (955cd45a2f6f226a2fdf44b329af1c8dde90cb38), and the credential file /var/log/.tacplus.acct, decoded with XOR key 0xEF.
    • BridgeAgent: persistence via a zabbix_agent.service systemd unit, encrypted configuration at /opt/.ICEauthority, and command-and-control (C2) over TLS on port 443.
    • IOS XR implants: /usr/bin/acpid (be6b27f429324a4af05a310d8ec9635e37c68a94), /pkg/bin/dhcpd_show_issu_status (1682b652a15bde732489f22809b0b7594c228fd3), /pkg/bin/hd (b149fa3a34bd585e7a674a4fd9538437bd06f514), and the persistence script /etc/rc.d/init.d/grub-rommon.
    • VMCI backdoor: /var/tmp/audit (13f0c2a598e3aa63856c032a96b110aed963f0e8), communicating over VMware Virtual Machine Communication Interface (VMCI) sockets.
    • Packet-triggered backdoor: /var/tmp/ping (5ba1242050b5b447052b210788a5a25593d6987d), activating on TCP ports 443, 541, 8443, and 10443 and UDP source port 40443 to destination port 500, triggered by the string sxcdewqaz!@#.

    The company’s full indicator set and YARA rules are available in its report.

    The activity parallels the router and TACACS+ traffic collection that a CISA-led joint advisory attributed to Salt Typhoon in August 2025, a separate Chinese espionage cluster that captured packet data from compromised routers to harvest administrator credentials across telecommunications networks.

    Ant blind ChinaLinked Cisco Credentials fire Hijacks Logs routers Security Steal
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

    Microsoft asks users to ignore ‘Antivirus is turned off’ errors

    Iran hostilities flare after US strike in strait of Hormuz; supertanker hits mines and catches fire – Middle East crisis live | US-Israel war on Iran

    U.S. Attacks Island in Strait of Hormuz; Iran Retaliates With Missile Fire

    More Details Emerge on Exploited PaperCut Vulnerabilities

    Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing Them

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    This Marine Died in the Iraq War. His Mother Asks, ‘What Was It For?’

    August 31, 2026

    Banks and insurers brace for biggest German pension upheaval in 20 years

    August 31, 2026

    Why Food Keeps Making Everybody Sick This Summer

    August 31, 2026

    China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

    August 31, 2026
    Latest Posts

    After Obamacare Cuts, Hospitals Are Treating More Uninsured Patients

    July 30, 2026

    Fifa World Cup plans: First lot of private cash could be received by end of October

    July 30, 2026

    Poland’s Leader Says Russian Missile May Have Struck Its Territory During Ukraine Attack

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    This Marine Died in the Iraq War. His Mother Asks, ‘What Was It For?’

    August 31, 2026

    Banks and insurers brace for biggest German pension upheaval in 20 years

    August 31, 2026

    Why Food Keeps Making Everybody Sick This Summer

    August 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.