China-Linked 'Fire Ant' Crew Breaks Into Cisco Routers to Steal Passwords and Hide Its Tracks

Sygnia says the espionage group has jumped from VMware servers to core network gear, tampering with logs and siphoning credentials from TACACS authentication servers.

ThreatVectr Newsdesk· 4 min read
A futuristic digital map of the Middle East with glowing network lines and a shadowy figure symbolizing cyber threats
Share

Key points

  • Sygnia has linked a China-aligned espionage group it calls Fire Ant to a fresh campaign targeting Cisco IOS XR routers, TACACS authentication servers and Linux management hosts.
  • The hackers previously focused on VMware hypervisors, the software that runs multiple virtual servers on one physical machine, and have now moved deeper into network plumbing.
  • Fire Ant is stealing login credentials and switching off or blinding security logs so defenders cannot see what happened.
  • The targets are high-value corporate and government networks, not home users.
  • Defenders are urged to check router configurations, audit TACACS accounts and review whether logging has been silently disabled.

A China-linked spying group is quietly rewiring the internal networks of large organisations, and this time it is going after the routers themselves.

Incident response firm Sygnia says the group, which it tracks as Fire Ant, has widened a long-running campaign. The hackers are now inside Cisco IOS XR routers (the heavy-duty machines that shuttle traffic across big corporate and carrier networks), TACACS servers (which check whether an engineer is allowed to log in to network gear), and the Linux computers administrators use to manage all of it. The findings were first reported by The Hacker News.

Fire Ant was already known for breaking into VMware hypervisors. Jumping to routers and authentication servers is a serious escalation. Once you own the router and the login server, you can read traffic, forge sessions, and quietly grant yourself access wherever you like.

Who is Fire Ant and what are they after?

Sygnia describes Fire Ant as a China-nexus cyber espionage actor, meaning a state-aligned group focused on stealing information rather than money. Their targets are high-value networks: think large enterprises, telecoms, and government-adjacent operators.

The goal in this campaign appears to be persistence and stealth. The hackers want long-term access to the plumbing that carries and authenticates traffic, and they want defenders to be unable to see them there.

How did the hackers get in?

According to Sygnia's investigation, Fire Ant is chaining together access across three layers of infrastructure. They pivot from previously compromised VMware environments onto the Linux hosts that manage network devices, then reach across to Cisco IOS XR routers and the TACACS servers that guard them.

Once on a router, the group harvests credentials passing through TACACS. That gives them working logins for other devices without having to hack each one individually. It is the network equivalent of stealing the master keyring from the building manager.

They also tamper with logging. Sygnia's investigators found evidence that security logs were disabled, filtered, or rerouted so that the hackers' commands never showed up in the records defenders rely on. If you cannot see the intruder, you cannot chase them out.

What is affected?

Layer Product or system What the hackers do here
Virtualisation VMware hypervisors Initial foothold, pivot point
Network routing Cisco IOS XR routers Traffic interception, log tampering
Authentication TACACS servers Credential theft
Management Linux admin hosts Lateral movement and tooling

Sygnia has not tied the campaign to a specific unpatched flaw with a CVE identifier in its public write-up. The intrusions look operator-driven, using stolen credentials and hands-on-keyboard techniques rather than a single push-button exploit.

Should ordinary people be worried?

Not directly. This is an espionage campaign against big organisations, not a scam aimed at consumers. There is no known consumer product to patch, and no customer data leak has been announced.

The practical impact for regular people is indirect: if your employer, bank or telecom operator runs the affected gear, their security teams will be busy this week checking router configurations, TACACS accounts and log pipelines. That is a good thing.

What should defenders do now?

Security teams running Cisco IOS XR should audit device configurations for unauthorised changes, verify that logging is intact and actually reaching the SIEM (the central system that collects security alerts), and rotate credentials stored on or used by TACACS servers. Sygnia also recommends treating VMware management networks and network-device management networks as equally sensitive, because Fire Ant clearly moves between them.

Assume, for the duration of the review, that any credential seen by a compromised TACACS server is burned.

© 2026 Threat Vectr