AI News Feed
Market watch
Companies

Fire Ant hackers turn Cisco routers into covert surveillance platforms, researchers say

A China-linked group called Fire Ant has expanded to Cisco routers, TACACS servers and Linux hosts, using compromised routers as spy platforms, according to Sygnia.

The group, known as Fire Ant, was recently observed compromising Cisco IOS XR routers, the researchers said. Once inside a router, the attackers do not simply use it to move laterally across the network. Instead, they turn it into a full operational platform, collecting traffic, establishing connections, manipulating command output and suppressing logging to avoid detection.

Fire Ant has also targeted TACACS servers, which administrators use to authenticate access to network hardware. By compromising these systems, the attackers can harvest credentials and weaken the reliability of audit logs, Sygnia found. In addition, the group was seen attacking Linux management hosts, deploying multiple persistent implants and backdoors, including a custom SSH backdoor and malware that spoofs legitimate software.

The campaign appears to be aimed at reaching environments beyond the initially compromised organization. Sygnia described this as a “target behind the target” scenario, noting that Fire Ant’s interest in a victim goes beyond compromising a single environment and aims to control infrastructure that enables visibility, collection and access beyond the immediate victim. The strategic value lies in the trust relationships the compromised organization maintains with connected environments.

Fire Ant was first observed in 2025, and little is known about it. Some researchers have noted significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously documented by Google, but there are also major differences that make attribution inconclusive, Sygnia said.