Fire Ant Expands Routers and Authentication Servers Compromise
Researchers at Sygnia, an incident response firm, have discovered that the China-nexus espionage group Fire Ant has expanded its operations to compromise Cisco IOS XR routers and TACACS authentication servers. This allows them to capture traffic, harvest administrator credentials, and suppress logs that defenders rely on.
The same actor was first documented in July 2025 for deep intrusions into VMware ESXi and vCenter environments. The new report describes the group operating at a lower layer, targeting routers, authentication servers, and Linux management hosts that carry traffic, authorize administrators, and record events.
The researchers assess a strong overlap with UNC3886, a China-linked group tracked by Google's Mandiant for targeting network edge and virtualization systems. However, the tooling has evolved rather than being reused wholesale.
On Cisco IOS XR routers, the operators deployed custom control-plane malware and created generic routing encapsulation tunnel interfaces that left no trace in device configuration files. On authentication infrastructure, a previously unreported toolkit named TacTap injected a malicious library into the tac_plus daemon to capture credentials as administrators authenticated.