China's Fire Ant APT Hijacks Cisco Routers for Network Intrusions
Cybersecurity firm Sygnia has detailed a sophisticated Chinese-linked hacking operation dubbed "Fire Ant" that compromised Cisco IOS XR routers to infiltrate organizations and pivot deeper into high-value networks. The group, which overlaps with the Mandiant-tracked threat actor UNC3886, deployed custom malware designed to seize control of routers, capture traffic from multiple devices, and exfiltrate data to attacker-controlled infrastructure. Fire Ant operators demonstrated a clear focus on "vantage points from across the environment" rather than relying on a single point of access, giving them broad visibility into victim networks.
Beyond router compromise, the campaign targeted the connective tissue between IT environments: hypervisors, access appliances, Linux management hosts, and authentication servers. Asaf Perlman, director of incident response at Sygnia, noted that Fire Ant "compromised the trust layer those systems depend on," exploiting infrastructure that many organizations treat as legacy. The attackers harvested critical credentials enabling wider access, then concealed their activity by manipulating logs, deleting files, and tampering with firewall rules. Sygnia reports that activity continued into 2026, evolving beyond hypervisor compromises to exploit third-party infrastructure relationships and reach critical networks. Defenders auditing their own perimeter exposure can start with a port scanner to identify reachable services on edge devices, while reviewing credential hygiene with a password checker to flag weak or reused router admin credentials.
Sygnia did not disclose the names of impacted organizations but warned that the affected infrastructure provided a launchpad toward other connected high-value environments, including critical infrastructure. The campaign underscores how edge networking equipment — often overlooked in patching cycles — remains an attractive target for state-sponsored actors seeking durable, stealthy access. Organizations running Cisco IOS XR should audit management plane access, verify firmware integrity, and monitor for anomalous configuration changes. Network teams can also assess outbound traffic patterns using a DNS leak test to detect unintended resolver exposure that could aid adversaries mapping internal communications.