Fire Ant Hackers Compromise Cisco Routers, Threaten Network Logs
A China-linked hacking group called Fire Ant has been found to have compromised Cisco routers, making network logs untrustworthy. The group used a technique that injects malicious code directly into a running TACACS+ authentication daemon, corrupting every administrative audit trail flowing through the server.
The investigation by Sygnia found that Fire Ant had moved from targeting hypervisors in 2025 to compromising the trusted infrastructure layer of enterprise networks. This includes routing traffic, authenticating administrators, and recording privileged activity. The group introduced two previously undocumented tools: BridgeAgent, a Linux backdoor, and TacTap, a TACACS credential-harvesting toolkit.
TacTap injects malicious code into the TACACS+ daemon, which is responsible for centralizing authentication, authorization, and accounting across routers, switches, and firewalls. This allows Fire Ant to intercept every new TACACS session at the moment of connection acceptance and forward the live session file descriptor to a backdoor process.