Chinese-linked Fire Ant hackers are compromising Cisco IOS XR routers and turning them into covert surveillance platforms, according to researchers at incident response firm Sygnia.
The attackers were identified after researchers discovered active Generic Routing Encapsulation (GRE) tunnel interfaces on Cisco routers that were not present in the devices’ running configurations or commit histories.
Sygnia said Fire Ant has expanded its operations beyond VMware hypervisors to target Cisco routers, TACACS authentication servers, and Linux management hosts.
Further analysis showed that Fire Ant deployed custom malware on compromised devices and established persistence through a fake system service that executed the implant at alternating intervals to reduce the risk of detection.
The malware can suppress selected syslog messages, conceal GRE tunnel information from legitimate administrators, create outbound Telnet connections to Fire Ant-controlled infrastructure, and provide interactive shell access without generating normal audit records.

Source: Sygnia
The attackers also used administrative access to capture network traffic from multiple routers before uploading the resulting PCAP files to an external FTP server.
These packet captures could reveal internal network topologies, management connections, authentication activity, routing relationships, and traffic exchanged with connected environments.
“This behavior shifts the role of the router from an intermediary device to a collection platform,” Sygnia explains.
“Once an attacker took control of a router, the device became a vantage point from which to observe traffic passing through trusted network paths.”
Fire Ant also created a hidden GRE tunnel between a compromised router and a legacy Linux server that served as a staging and reconnaissance system.
From this foothold, the attackers scanned connected high-value environments, including systems associated with critical infrastructure. Their probes targeted ports commonly used for SSH, web services, SMB/RPC, and Remote Desktop Protocol (RDP).
Sygnia believes the campaign was designed to compromise trusted infrastructure and use it as a covert bridge into connected high-value networks. The researchers refer to this tactic as “going behind the target.”
.jpg)
Source: Sygnia
Researchers also identified a previously undocumented backdoor named “BridgeAgent.” The malware disguises itself as a legitimate Zabbix monitoring agent on compromised Linux systems.
BridgeAgent persists as a root-level systemd service and supports TLS-protected reverse shells, as well as the execution of additional payloads on infected hosts.
.jpg)
Source: Sygnia
Sygnia said Fire Ant’s activity overlaps significantly with UNC3886, a Chinese espionage group previously documented by Google. However, the researchers identified differences in file names, installation paths, and implementation details.
Researchers warned that Fire Ant systematically modifies system logs and other records to conceal its activity. The attackers also change file timestamps, potentially erasing evidence useful to incident responders.
As a result, organizations should validate logs collected from compromised infrastructure against independent telemetry, including network monitoring data, authentication records, router configurations, and endpoint activity.
Sygnia’s report includes an extensive list of indicators of compromise (IoCs), threat-hunting guidance, and YARA rules designed to help defenders detect Fire Ant activity.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




