Fire Ant Uses Trusted Infrastructure to Reach High-Value Networks
Chinese-linked cyber espionage group Fire Ant has been quietly expanding its hacking capabilities over the past year, moving from individual computers to compromising trusted infrastructure that connects them. According to a new report by Sygnia, Fire Ant has compromised hypervisors, routers, authentication servers, and Linux management hosts to gain access to high-value networks.
The investigation began with an anomaly on a Cisco IOS XR router where a tunnel interface became operational without any corresponding configuration or commit history. This discrepancy led investigators to discover that the router's own records could no longer be trusted to reflect what the device was actually doing.
Fire Ant built a custom toolkit for the router's internals, hooking into logging, command execution, and routing functions directly. The group also used deep, persistent backdoors on Linux systems, some of which had remained dormant since 2025 and were disguised as normal system services.