Fire Ant Expands Reach with Sophisticated Cisco Router Espionage Campaign
A sophisticated China-nexus threat actor known as Fire Ant has expanded its reach into trusted environments by targeting Cisco routers in an espionage campaign.
The actor, which gained recognition in 2025 after abusing VMware environments, collected network traffic and administrative credentials, mapped routes and trusted relationships, established multiple persistent access mechanisms, and manipulated evidence to reduce the likelihood of detection.
Sygnia's investigation began after unusual activity was observed in a Cisco IOS XR router. Researchers found that a generic routing encapsulation tunnel interface was operational, even though a running configuration and commit history could not explain how it was created.
The attackers compromised an access choke point called a Terminal Access Controller Access Control Point (TACACS) to interfere with the authentication process and steal credentials. Novel attack tools were used, including a Zabbix-masquerading implant for tunneling and persistence, dubbed BridgeAgent, and a second tool, TacTap, for gathering credentials.
Perlman says security teams should restrict privileged access to network and management infrastructure using dedicated administrative paths, monitor for unexpected generic routing encapsulation or tunnel interfaces, and centralize router authentication and network telemetry outside of managed devices.