logo

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

ID: e0fdca8e-ca56-5260-8806-b98ddd85d1e4

STIX ID: report--e0fdca8e-ca56-5260-8806-b98ddd85d1e4

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-08-31

Date Updated: 2026-08-31

Author: [email protected] (The Hacker News)

...
...

Sygnia attributed a sophisticated China-nexus espionage campaign (tracked as Fire Ant and linked to public reporting on UNC3886) that escalated from VMware hypervisors into Cisco IOS XR routers, TACACS servers, and Linux management hosts; the actor used purpose-built router implants, a TACACS credential-stealer (TacTap), a Linux backdoor (BridgeAgent), and other rootkits/backdoors to capture packet data, harvest credentials, suppress logging, and maintain long-term access, with a full set of IoCs published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.