Skip to content
Back to Guavy Wire
Stocks

Fire Ant Hackers Compromise Cisco Routers, Threaten Network Logs

Instruments
CSCO
Share

A China-linked hacking group called Fire Ant has been found to have compromised Cisco routers, making network logs untrustworthy. The group used a technique that injects malicious code directly into a running TACACS+ authentication daemon, corrupting every administrative audit trail flowing through the server.

The investigation by Sygnia found that Fire Ant had moved from targeting hypervisors in 2025 to compromising the trusted infrastructure layer of enterprise networks. This includes routing traffic, authenticating administrators, and recording privileged activity. The group introduced two previously undocumented tools: BridgeAgent, a Linux backdoor, and TacTap, a TACACS credential-harvesting toolkit.

TacTap injects malicious code into the TACACS+ daemon, which is responsible for centralizing authentication, authorization, and accounting across routers, switches, and firewalls. This allows Fire Ant to intercept every new TACACS session at the moment of connection acceptance and forward the live session file descriptor to a backdoor process.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc