Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unveiling the Shadowy World of China-Linked Fire Ant: A Comprehensive Analysis of the Malicious Attack on Cisco Routers




China-Linked Fire Ant, a China-nexus cyber espionage actor, has expanded its malicious campaign to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, allowing it to steal credentials and manipulate network traffic. This attack highlights the growing threat of China-linked cyber espionage and underscores the need for organizations to prioritize their network security and implement robust measures to prevent similar attacks.

  • Fire Ant, a China-nexus cyber espionage actor, has expanded its campaign to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts.
  • The attack demonstrates an unprecedented level of sophistication, allowing Fire Ant to intercept sensitive information and manipulate network traffic.
  • The attack involves the use of purpose-built malware designed for the IOS XR control plane, which was used to capture packet captures and upload them to external FTP servers.
  • Fire Ant also deployed a Linux backdoor called BridgeAgent, which masqueraded as a Zabbix monitoring agent and polled the attacker's infrastructure for commands.
  • The attack highlights the growing threat of China-linked cyber espionage and has significant implications for the security of critical infrastructure.
  • Several indicators of compromise (IoCs) have been published, including TacTap, BridgeAgent, and the injected library /lib/libseconfd.so.



  • In a recent revelation, a China-nexus cyber espionage actor, tracked as Fire Ant, has expanded its long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. This malicious attack, uncovered by the incident response firm Sygnia, has significant implications for the security of critical infrastructure and highlights the growing threat of China-linked cyber espionage.

    The Fire Ant actor, which has been linked to public reporting on UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network edge devices, has demonstrated an unprecedented level of sophistication in its attack vector. By compromising Cisco routers, Fire Ant gains control over traffic moving through trusted network paths, effectively allowing it to intercept sensitive information and manipulate network traffic.

    The attack began with an anomaly on a Cisco IOS XR router, where a Generic Routing Encapsulation (GRE) tunnel interface was operating with no running configuration or commit history to explain how it had been created. Sygnia, the firm that investigated the intrusion, did not identify how the actor first gained access to the router. Tracing the tunnel led investigators to a legacy Linux system, from which Fire Ant ran repeated connection attempts and port probing against administrative and service ports on connected networks, including SSH, HTTP, SMB, and RDP.

    The router malware was purpose-built for the IOS XR control plane rather than a generic Linux appliance. One component embedded a modified system library that checked each outgoing log message for the string "Health" and forwarded it only when the string was present. A separate component altered the router's command-execution path to append an | exclude filter to show commands, hiding the attacker's tunnel configuration from administrators inspecting the device.

    Fire Ant then used the routers to capture packet captures (PCAPs) from multiple Cisco devices. The captures were uploaded to external FTP servers, one of which appeared to have been installed the same day the uploads took place. On the TACACS server, Sygnia identified a credential-collection toolset it tracks as TacTap. An injector named acppid loaded a malicious library into the running tac_plus authentication process, allowing it to hook the functions that accept new connections and pass the live session handles to a second process over a local Unix socket.

    The captured credentials were written to /var/log/.tacplus.acct and lightly obfuscated with a single-byte XOR key of 0xEF. This specific tac_plus library-injection technique has not been publicly described before, making it a notable evolution of Fire Ant's TACACS-focused credential collection tradecraft.

    Credential theft from TACACS servers is established tradecraft for the cluster, as Mandiant has previously documented UNC3886 deploying a TACACS+ sniffer called LOOKOVER and replacing the tac_plus daemon with a backdoored version to log credentials. Sygnia also recovered a second new tool, a Linux backdoor it called BridgeAgent, which was deployed on the tunnel-connected host and masqueraded as a Zabbix monitoring agent.

    The implant persisted via a zabbix_agent.service systemd unit running as root, disguised its process as /usr/bin/gnome-shell, and polled the attacker's infrastructure over TLS on port 443 for commands and reverse-shell instructions. Across the Linux management hosts, Fire Ant built a durable access layer using the open-source Medusa and REPTILE rootkits, custom SSH backdoors, and binaries renamed and timestamped to impersonate the SentinelOne and Cybereason endpoint security agents.

    Several of these components were planted in 2025 and reused for hands-on activity in 2026. At least one backdoor kept running in memory after its file had been deleted from disk, Sygnia said. The actor also worked to undermine the evidence itself by suppressing router logs, SNMP traps, and authentication requests, disabling SELinux on the Linux hosts, rewriting login-history records, and removing entries for privileged commands from system logs.

    Sygnia published the following indicators of compromise (IoCs) - TacTap, the injector /usr/sbin/acppid (SHA1 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00), the injected library /lib/libseconfd.so (955cd45a2f6f226a2fdf44b329af1c8dde90cb38), and the credential file /var/log/.tacplus.acct, decoded with XOR key 0xEF.

    BridgeAgent persistence via a zabbix_agent.service systemd unit, encrypted configuration at /opt/.ICEauthority, and command-and-control (C2) over TLS on port 443. IOS XR implants /usr/bin/acpid (be6b27f429324a4af05a310d8ec9635e37c68a94), pkg/bin/dhcpd_show_issu_status (1682b652a15bde732489f22809b0b7594c228fd3), pkg/bin/hd (b149fa3a34bd585e7a674a4fd9538437bd06f514), and the persistence script /etc/rc.d/init.d/grub-rommon.

    VMCI backdoor /var/tmp/audit (13f0c2a598e3aa63856c032a96b110aed963f0e8), communicating over VMware Virtual Machine Communication Interface (VMCI) sockets. Packet-triggered backdoor /var/tmp/ping (5ba1242050b5b447052b210788a5a25593d6987d), activating on TCP ports 443, 541, 8443, and 10443 and UDP source port 40443 to destination port 500, triggered by the string sxcdewqaz!@#.

    The activity parallels the router and TACACS+ traffic collection that a CISA-led joint advisory attributed to Salt Typhoon in August 2025, a separate Chinese espionage cluster that captured packet data from compromised routers to harvest administrator credentials across telecommunications networks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unveiling-the-Shadowy-World-of-China-Linked-Fire-Ant-A-Comprehensive-Analysis-of-the-Malicious-Attack-on-Cisco-Routers-ehn.shtml

  • https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html


  • Published: Mon Aug 31 06:07:31 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us