VMTech
Discuss a project

Fire Ant Campaign Targets Cisco Routers and TACACS Servers

Fire Ant Campaign Targets Cisco Routers and TACACS Servers

China-linked cyber espionage actor Fire Ant has expanded its operations from VMware environments into Cisco IOS XR routers, TACACS servers and Linux management hosts. Sygnia’s investigation found the actor using compromised routers to capture network traffic, harvest credentials and suppress logs and telemetry that could expose its activity.

The campaign involved a suspicious Generic Routing Encapsulation tunnel on a Cisco IOS XR router. The interface had no running configuration or commit history explaining its creation. Investigators traced the tunnel to a legacy Linux system that made repeated connection attempts and probed SSH, HTTP, SMB and RDP ports on connected networks.

Router control provides both access and visibility

Sygnia said Fire Ant used purpose-built malware for the IOS XR control plane, not generic Linux tooling. One modified system library inspected outgoing log messages and forwarded only those containing the string Health. Another component changed the command-execution path to add an | exclude filter to show commands, concealing the attacker’s tunnel configuration from administrators.

The group also captured PCAP data from multiple Cisco devices and uploaded it to external FTP servers. Sygnia assessed that Fire Ant explored paths to connected high-value environments, including critical infrastructure, but observed scanning and connection attempts rather than a confirmed compromise of those environments.

The investigation adds weight to the concerns reflected in Cisco vulnerability and attack trend briefing about Cisco vulnerabilities, ClickFix chains and growing AI-agent incidents, while illustrating how control of network infrastructure can limit the evidence available to defenders.

TACACS credential theft and durable Linux access

On a TACACS server, Sygnia identified a credential collection set named TacTap. Its acppid injector loaded a malicious library into the running tac_plus process, hooked functions that accepted new connections, and passed live session handles to another process over a local Unix socket. Captured credentials were stored in /var/log/.tacplus.acct with single-byte XOR obfuscation using key 0xEF.

Sygnia also recovered BridgeAgent, a Linux backdoor disguised as a Zabbix monitoring agent. It persisted through a root-run zabbix_agent.service systemd unit, presented itself as /usr/bin/gnome-shell, and polled attacker infrastructure over TLS on port 443 for commands and reverse-shell instructions.

Across Linux management hosts, Fire Ant deployed Medusa and REPTILE rootkits, custom SSH backdoors, and binaries made to resemble SentinelOne and Cybereason endpoint agents. The actor disabled SELinux, rewrote login history and removed privileged-command entries from system logs. Sygnia noted that at least one backdoor remained active in memory after its file was deleted.

Business implication

Security teams should treat routers, TACACS servers, hypervisors and jump hosts as first-class forensic assets. The practical response is to validate device logs against memory, disk, network, authentication and configuration evidence, because a compromised control plane can alter or suppress the telemetry on which incident investigations depend.

#cybersecurity#ciscosecurity#threatintel#networksecurity
Open analytics
On the site 0 views
min read 4 31.08.2026
Instagram

Fire Ant Campaign Targets Cisco Routers and TACACS Servers

Open the post on Instagram ↗