Sygnia Reveals New Activity by China-Nexus Threat Actor Fire Ant Targeting Trusted Infrastructure
Sygnia says Fire Ant used novel tools to collect credentials, hide activity and reach other connected environments through trusted infrastructure.
- On Sunday, Sygnia released a report detailing an espionage campaign by the China-nexus actor Fire Ant, which is actively compromising Cisco IOS XR routers and TACACS servers to infiltrate high-value networks and critical infrastructure.
- Expanding beyond 2025 operations targeting VMware ESXi and vCenter environments, Fire Ant shifted focus to strategic infrastructure abuse, marking a significant evolution in the actor's targeting approach.
- Researchers uncovered novel tools including BridgeAgent, a Zabbix-masquerading implant for tunneling, and TacTap, a credential-collection toolset. Asaf Perlman, Director of Incident Response at Sygnia, confirmed attackers manipulated logs and firewall rules to suppress evidence.
- The campaign exploits "Target behind the target" infrastructure that other systems depend on for communication. Perlman warned that compromising these authentication hosts grants the actor visibility into connected high-value environments.
- Perlman recommends that security teams centralize router authentication and restrict privileged access to management hosts to prevent attackers from manipulating evidence on compromised systems.
10 Articles
10 Articles
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
Sygnia Reveals New Activity by China-Nexus Threat Actor Fire Ant Targeting Trusted Infrastructure
Incident Response leader reveals long-running espionage activity abusing routers, authentication systems and Linux management hosts to collect intelligence and explore paths toward connected high-value environments. SINGAPORE & TEL-AVIV, Israel & NEW YORK–(BUSINESS WIRE)–Sygnia, the foremost global cyber readiness and response team, released the findings of their investigation into ongoing activity by a China-nexus threat actor, …
State-linked actor targets Cisco routers for espionage | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security Consulting
A sophisticated China-nexus actor is abusing routers using the Cisco IOS XR operating system in an espionage campaign that reaches into high-value networks and critical infrastructure, according to a report released Sunday by Sygnia. The actor, tracked as Fire Ant, gained wide recognition in 2025 after abusing VMware environments. Researchers said this new campaign represents […] Thank you for subscribing to our RSS feed! The post State-linked …
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor
Sygnia Reveals New Activity by China-Nexus Threat Actor Fire Ant ...
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











