China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
- ID
- 19769
- Status
- summarized
- Published
- 31 Aug 2026, 5:04 PM
- Fetched
- 31 Aug 2026, 7:14 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 31 Aug 2026, 7:14 PM
- Tags
- Audience
- developers
What happened
A China-nexus espionage group tracked as Fire Ant (overlapping with UNC3886) has expanded from compromising VMware ESXi/vCenter environments to hijacking Cisco IOS XR routers, TACACS servers, and Linux management hosts, turning routers into traffic-collection platforms that harvest credentials and suppress logging telemetry. Sygnia's investigation began after finding an unexplained GRE tunnel interface on a Cisco router with no commit history, which led to a legacy Linux system used for port probing against administrative services.
Why it matters
If your organization runs Cisco IOS XR routers or TACACS authentication, check for unexplained GRE tunnel interfaces and audit legacy Linux management hosts—this group specifically suppresses logs to stay hidden, so normal monitoring won't catch them. For most SaaS founders and developers not operating this class of network gear, there is no direct action to take.
Discussion angle
The technique of creating a GRE tunnel with no commit history is a concrete indicator-of-compromise worth showing—discuss how network devices that lack robust change-tracking become blind spots that attackers can exploit without triggering standard SIEM alerts.