China linked cyber espionage activity tracked as Fire Ant has expanded beyond VMware environments to target Cisco IOS XR routers, Terminal Access Controller Access Control System (TACACS) servers, and Linux management hosts that support high value enterprise networks, according to incident response firm Sygnia. Researchers said the operation turned compromised routers into collection platforms capable of capturing network traffic, harvesting credentials, and limiting logging and telemetry that security teams typically use during investigations. While the actor explored routes into connected high value environments, including critical infrastructure, Sygnia stated that the observed activity in those environments was limited to scanning and connection attempts, with no confirmed compromise. The company also noted similarities between this campaign and publicly reported activity associated with the China linked espionage group UNC3886, although it stopped short of making a definitive attribution.
The investigation began after analysts detected unusual activity on a Cisco IOS XR router where a Generic Routing Encapsulation tunnel interface was active despite having no configuration or commit history explaining its creation. Tracing the tunnel led investigators to a legacy Linux management system that was used to perform repeated connection attempts and port scanning across administrative services including SSH, HTTP, SMB, and RDP. Sygnia found that the malware deployed on Cisco routers had been specifically developed for the IOS XR control plane rather than adapted from generic Linux malware. One component modified a system library so that only log messages containing a specific keyword were forwarded, while another altered command execution by automatically appending filters that concealed malicious tunnel configurations from administrators reviewing router settings. Fire Ant also used compromised routers to capture packet data from multiple Cisco devices before uploading those captures to external FTP servers that appeared to have been established shortly before the transfers occurred.
Researchers also uncovered new tools used against TACACS authentication servers and Linux management systems. On TACACS servers, Fire Ant deployed a credential collection framework named TacTap, which injected a malicious library into the running tac plus authentication process to intercept live authentication sessions and store captured credentials in an obfuscated log file. According to Sygnia, this specific library injection technique has not previously been publicly documented, although similar credential theft methods involving TACACS infrastructure have been linked to UNC3886 in earlier investigations. The company also discovered a Linux backdoor it named BridgeAgent, disguised as a Zabbix monitoring agent. The malware established persistence through a systemd service running with root privileges while presenting itself as a legitimate gnome shell process. It communicated with attacker infrastructure over encrypted TLS connections on port 443 and accepted remote commands, including reverse shell instructions. Across Linux management hosts, Fire Ant further maintained long term access using Medusa and REPTILE rootkits, custom SSH backdoors, and renamed binaries designed to resemble SentinelOne and Cybereason security software. Some of these tools were originally deployed during 2025 and remained active during operations observed in 2026.
Sygnia also reported that the actor attempted to reduce the availability of forensic evidence by suppressing router logs, SNMP traps, and authentication records, disabling SELinux on Linux hosts, modifying login histories, and removing records of privileged commands. Based on its findings, the company advised organizations to treat routers, TACACS servers, hypervisors, and jump hosts as critical forensic assets during incident response activities. Researchers recommended validating evidence using memory, disk, network, authentication, and configuration data rather than relying on a single source of telemetry. Sygnia also published a comprehensive set of indicators of compromise and YARA detection rules covering tools including TacTap, BridgeAgent, IOS XR implants, VMware communication backdoors, and packet triggered malware. The observed activity also reflects techniques previously highlighted in a CISA led advisory published in 2025 that described another China linked espionage operation using compromised routers and TACACS infrastructure to capture network traffic and collect administrator credentials across telecommunications environments.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.