High

Fire Ant, Cisco, UNC3886, Espionage, Network Security, China

Fire Ant Hijacks Cisco Routers to Blind Defenders

China-linked Fire Ant is hijacking Cisco IOS XR routers to steal credentials and suppress logs. What Sygnia found, the UNC3886 overlap, and how to respond.

Fire Ant, a China-nexus cyber espionage group, is hijacking Cisco IOS XR routers to steal credentials and suppress the security logs defenders rely on, expanding a long-running campaign from VMware hypervisors onto network infrastructure. According to incident response firm Sygnia, the actor compromised Cisco routers, TACACS (Terminal Access Controller Access-Control System) servers, and Linux management hosts, turning the routers into collection platforms that capture network traffic, harvest credentials, and blind telemetry. The campaign strongly overlaps with public reporting on UNC3886, though Sygnia stops short of a conclusive attribution.

The insight Sygnia draws is that controlling a router is not just about reach, it is about perspective: an attacker sitting on trusted network paths sees the traffic moving through them. The group used its foothold to explore routes toward connected high-value environments, including critical infrastructure, though activity against those networks was limited to scanning and connection attempts rather than confirmed compromise. This 2026 activity follows Sygnia's July 2025 disclosure of Fire Ant exploiting VMware, so the same actor is now demonstrating depth across both the virtualization and network layers.

Why are routers such a valuable target?

Because they sit at a trusted chokepoint and are poorly monitored. Network devices rarely run endpoint detection, their logs are easy to tamper with once you have control, and defenders often treat them as infrastructure rather than assets to hunt on. By suppressing logging and telemetry from the router itself, Fire Ant removes the very evidence an investigation would need, which is why edge-device compromise is a recurring theme in state-linked espionage. Controlling the authentication path through TACACS servers compounds the problem, giving the actor a route to credentials across the managed network.

Item

Detail

Actor

Fire Ant (China-nexus), overlaps UNC3886

Reported by

Sygnia

Targets

Cisco IOS XR routers, TACACS servers, Linux management hosts

Goal

Traffic capture, credential harvesting, log and telemetry suppression

Onward activity

Scanning and connection attempts toward critical infrastructure

Background

Follows Sygnia's July 2025 Fire Ant VMware disclosure

How should defenders respond?

Treat network devices as first-class hunt surfaces, not trusted furniture. That means centralizing router and TACACS logs off the device so they cannot be silently suppressed, monitoring for configuration and authentication anomalies, restricting and closely watching management-plane access, and validating device integrity rather than assuming it. Because the actor's aim is to blind you, the countermeasure is to keep an independent record of what your infrastructure is doing.

Our read

Fire Ant is a reminder that the assets defenders monitor least are the ones sophisticated actors target most. A router that captures traffic and erases its own logs is an intelligence platform, and no endpoint agent will tell you it is there. This is where continuous verification of the network edge matters: confirm from outside the device that its configuration, authentication paths, and telemetry are intact, rather than trusting infrastructure that is designed to be trusted. The perspective an attacker gains from a router is exactly the perspective a defender must not cede.

Reporting by The Hacker News; campaign detail and attribution assessment per Sygnia. Sources linked above.

Related: Continuous verification vs annual pentest and What is the MITRE ATT&CK framework?.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.