Summary
- Sygnia observed Fire Ant compromising Cisco IOS XR routers, TACACS infrastructure, and Linux management systems.
- The actor used trusted infrastructure for traffic collection, credential theft, persistence, and access towards connected environments.
- Fire Ant’s China-nexus attribution is Sygnia’s assessment and should not be treated as independently established state attribution.
Sygnia has disclosed a new phase of activity by the threat actor it tracks as Fire Ant, with the group moving into routers, authentication infrastructure, and Linux management systems that sit at the trust boundaries between high-value networks.
The incident-response company describes Fire Ant as a China-nexus threat actor. That attribution is Sygnia’s assessment rather than an independently established conclusion about state sponsorship.
The technical activity is notable for the systems the attackers chose to compromise. Sygnia says the 2026 operation targeted Cisco IOS XR routers and used them as platforms for covert connectivity, traffic collection, and access into connected environments.
The researchers also identified compromise of TACACS authentication infrastructure and Linux management hosts.
Those systems perform functions far beyond those of an ordinary endpoint. Routers decide how traffic moves, authentication servers determine whether administrative activity is trusted, and management hosts often provide the paths through which infrastructure is configured and monitored.
Sygnia says the actor used compromised TACACS infrastructure to intercept administrative authentication flows and collect credentials. It also found activity intended to reduce confidence in audit records by suppressing authentication, authorisation, and accounting requests.
The researchers identified two previously undocumented tools. BridgeAgent is described as a Linux implant used for tunnelling and persistence, while TacTap is a credential-collection toolset associated with compromised TACACS infrastructure.
Persistence extended beyond those components. Sygnia reported SSH backdoors, packet-triggered access mechanisms, and long-lived implants across Linux management systems, together with techniques intended to reduce obvious evidence of attacker activity.
The router compromise is particularly consequential because configuration and telemetry from network infrastructure normally help explain what occurred elsewhere.
During the investigation, Sygnia identified a Generic Routing Encapsulation tunnel operating on a Cisco IOS XR router that could not be explained by the device’s expected running configuration or normal configuration history. The discrepancy contributed to the discovery that the networking equipment itself had become part of the attacker’s infrastructure.
Sygnia also reported log manipulation, filtered command output, suppressed SNMP traps, file deletion, firewall-rule changes, and the disabling of SELinux on compromised Linux systems.
Those actions complicate incident reconstruction because the attacker is interfering with systems that defenders would normally rely upon as sources of authoritative evidence.
The company links the latest activity to Fire Ant operations it investigated in 2025 involving VMware ESXi and vCenter infrastructure. Across both phases, the common feature is the targeting of infrastructure with trust or administrative reach over other systems.
That can produce access disproportionate to the number of devices compromised. An endpoint may expose one user or workstation; an authentication chokepoint can expose privileged credentials, while a router or management host can reveal or provide paths into multiple connected environments.
The approach also makes defining the incident boundary more difficult. Where a router connects separate organisations, or a management environment maintains access into another high-value estate, investigating only the initially compromised network can leave part of the attacker’s route unexplored.
Sygnia says Fire Ant used trusted infrastructure to collect intelligence and investigate possible access towards connected organisations. That claim reflects the company’s incident-response findings and attribution.
The broader problem is one of trust architecture. Network devices and authentication systems are not simply supporting equipment around the edge of an incident; they can become the mechanism through which an attacker controls connectivity, captures credentials, conceals activity, and expands the scope of a compromise.
Once those systems are themselves untrusted, normal assumptions about routing records, authentication logs, and management telemetry have to be reconsidered. The investigation then moves from looking through trusted infrastructure for evidence to establishing whether the infrastructure producing that evidence has also been manipulated.




