China-linked "Fire Ant" hackers nest inside telecoms routers to swarm critical infrastructure

Threat actors deploy a "target behind the target" strategy to stealthily tunnel into high-value environments.

Share
Fire Ant is believed to be linked to the Chinese state - although Beijing has explicitly denied being linked to the threat actor (Image: Unsplash)
Fire Ant is believed to be linked to the Chinese state - although Beijing has explicitly denied being linked to the threat actor (Image: Unsplash)

China-linked threat actors are allegedly targeting critical infrastructure by hijacking routers that power some of the world’s largest telecommunications and internet networks.

A group tracked as Fire Ant is reported to have leveraged novel attack tools to turn Cisco IOS XR routers into operational platforms, enabling them to strike at critical systems that "route, authenticate, connect, and manage high-value environments".

The security firm Sygnia has published new research warning that Fire Ant has expanded its tactics and techniques beyond its 2025 activity, which saw the group establish persistence within virtualization infrastructure targeting VMware ESXi and vCenter environments.

Asaf Perlman, Director of Incident Response at Sygnia, said: "Fire Ant didn’t just compromise systems. It compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure many organizations overlook as legacy technology became the attacker’s vantage point for reach, visibility, and control."

The stealthy threat actors used a "target behind the target" strategy, compromising the routers, authentication systems and management infrastructure trusted by one organization to create pathways toward other connected high-value networks, including critical infrastructure.

Rather than attacking those critical systems directly, Fire Ant established itself inside the technology responsible for connecting networks and controlling access.

From there, the group could collect traffic and credentials, investigate routes into other environments, and conceal evidence of its activities.

Investigators discovered a GRE tunnel operating on a compromised Cisco IOS XR router, despite no corresponding running configuration or commit history to explain its creation.

Tracing the other end of the tunnel led them to a compromised legacy Linux system. From that machine, Fire Ant made repeated connection attempts and port scans against connected high-value environments, including systems associated with critical infrastructure.

The probes targeted common administrative and service ports, including SSH, HTTP, HTTPS, SMB, RPC, and Remote Desktop Protocol.

In other words, infrastructure belonging to one compromised environment had become a bridge through which the attackers could explore what lay beyond it.

Tunneling into routers

Fire Ant's control of the Cisco equipment went considerably deeper than simply obtaining administrative credentials.

Sygnia found malware purpose-built for the IOS XR control plane, interacting directly with functions responsible for logging, command execution, routing, Virtual Routing and Forwarding (VRF), authentication, and Telnet management.

The attackers also turned compromised routers into surveillance platforms, capturing network traffic from multiple Cisco devices and uploading the resulting PCAP files to external FTP infrastructure.

Those packet captures could expose internal network topology, management connections, authentication flows, routing relationships and traffic moving between connected environments.

READ MORE: "Iranian hackers" shut down a UK power station. The next incident could be much worse

One malicious component disguised itself as "acpid", a legitimate Linux system process, and tampered with the router's logging system to selectively suppress evidence of activity.

Another provided outbound connectivity within the router's native network environment.

Fire Ant even manipulated what administrators could see when they interrogated compromised equipment.

Sygnia reverse-engineered a component that modified the IOS XR command-execution path to append exclusion filters to "show' commands.

Investigators separately recovered command history containing filters matching details associated with the suspicious tunnel, including its interface, source, destination, and VRF.

In effect, the attackers had compromised both the router and some of the mechanisms defenders might use to discover the intrusion.

Stealing credentials

Fire Ant also compromised TACACS infrastructure that is used to authenticate and record administrative access to network equipment.

Sygnia discovered a previously undocumented credential-collection toolset it named TacTap.

The injected malware intercepted newly accepted TACACS connections and passed their connection descriptors to another malicious process through a local Unix socket.

Investigators recovered TACACS-related credential material from a hidden file, where it had been obfuscated using single-byte XOR.

The compromise was particularly significant because TACACS systems can sit at an administrative chokepoint, authenticating administrators, authorizing commands and recording their activity across network infrastructure.

Fire Ant established multiple additional access mechanisms across compromised Linux management infrastructure.

Sygnia found Medusa-related rootkit components, custom SSH backdoors, credential harvesting, masqueraded executables and a packet-triggered remote-access implant.

Some components had been installed during 2025 and remained available for operations observed in 2026.

READ MORE: FBI smashes "Chinese state-linked botnet platform" targeting US critical infrastructure

One particularly stealthy backdoor monitored raw network traffic for secret activation markers rather than simply exposing a conventional listening service.

Once triggered, it could create an interactive shell for Fire Ant's operators. The malware also disabled Bash history, helping prevent commands from being recorded.

Fire Ant then attacked the evidence defenders would normally use to reconstruct the intrusion.

Sygnia found router logging was suppressed, command outputs manipulated, Linux login records altered, and malicious executables deleted while their processes continued running in memory.

Other malware was disguised to resemble SentinelOne and Cybereason security software, with timestamps manipulated to help malicious files blend into their surroundings.

Sygnia said Fire Ant's behavior strongly overlaps with publicly reported activity attributed to UNC3886, a China-nexus espionage cluster previously associated with attacks against virtualization platforms, edge devices and network infrastructure.

The Chinese government has denied links to UNC3886.

After Singapore disclosed in 2025 that the group was attacking its critical infrastructure, the Chinese Embassy rejected reports connecting the hackers to China as "groundless smears and accusations."

Beijing said it was firmly opposed to cyberattacks and "does not encourage, support or condone hacking activities."

Singapore itself stopped short of attributing UNC3886 to the Chinese state, although cybersecurity researchers at Mandiant have described it as a China-nexus espionage group.

Follow Machine on LinkedIn