Fire Ant Evolves: China-Nexus Threat Actor Targets Trusted Infrastructure
A China-nexus threat actor, tracked by Sygnia as 'Fire Ant', has been targeting trusted infrastructure to collect intelligence and explore paths toward connected high-value environments. The threat actor's activity in 2026 represents an evolution of their focus beyond deep persistence within virtualization infrastructure.
According to the findings released by Sygnia, Fire Ant leveraged novel attack tools and methods to target Cisco IOS XR routers, turning them into operational platforms that suppress evidence of threat actor activity. This allowed Fire Ant to collect traffic and credentials, and explore other access points with the goal of spreading to other organizations.
Sygnia's investigation uncovered two novel tools used by Fire Ant: a masquerading implant called BridgeAgent, which is configured for tunnelling and persistence through a zabbix_agent.service systemd unit, and a TACACS credential-collection toolset called TacTap. The actor also established resilient access layers through long-lived implants across Linux management infrastructure.