China-linked Fire Ant group hijacks Cisco routers and TACACS servers to spy on networks
Incident response firm Sygnia says the espionage group it tracks as Fire Ant has expanded from VMware hypervisors into Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, turning them into hidden collection points for traffic and credentials.
Sygnia, the incident response firm that investigated the intrusion, says a China-nexus group it tracks as Fire Ant - first documented in 2025 targeting VMware ESXi and vCenter - has now expanded into Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The routers were turned into collection platforms that capture traffic and hide the intrusion from defenders, and a previously undocumented credential-theft technique was found on the TACACS servers. Sygnia says the actor probed toward connected critical infrastructure but found only scanning, not confirmed compromise, and links the activity to prior reporting on UNC3886 without confirming that identity. Funding disclosure: not applicable (incident response research, not a funded clinical or commercial study). Cisco Systems trades as $CSCO; mentioned only as the vendor whose routers were targeted, not the subject of the story.