September 8, 2026
By esentry Team

Fire Ant Targets Trusted Network Infrastructure

A China-linked threat actor known as Fire Ant has been observed compromising Cisco routers and other trusted network infrastructure to steal credentials, monitor network traffic and evade security monitoring.

The attackers targeted Cisco IOS XR routers, TACACS authentication servers, and Linux management systems. They used hidden tunnels, malicious software, and log manipulation to maintain access while making their activity difficult to detect.

Technical Details

Fire Ant was observed:

  • Creating hidden GRE tunnels on compromised Cisco routers.
  • Capturing network traffic and packet data.
  • Modifying router logs and command output to hide malicious activity.
  • Compromising TACACS servers to capture administrator credentials.
  • Deploying backdoors and rootkits on Linux management systems.
  • Using legitimate-looking services, including Zabbix, to disguise malicious activity.
  • Moving through trusted infrastructure to identify and access high-value systems.

Impact

Successful compromise could allow attackers to:

  • Steal privileged administrator credentials.
  • Monitor sensitive network communications.
  • Maintain persistent access to network infrastructure.
  • Hide malicious activity from security teams.
  • Use trusted systems to move toward critical environments.

Recommendations

Organizations are advised to:

  • Review Cisco routers for unexpected GRE tunnels and configuration changes.
  • Inspect TACACS servers for unauthorized processes, files, and authentication activity.
  • Review Linux management systems for unknown services, backdoors, and rootkits.
  • Rotate privileged credentials if authentication infrastructure is suspected to be compromised.
  • Monitor for unusual outbound network connections and packet-capture activity.
  • Forward logs to centralized and independent logging systems to prevent local log manipulation.
  • Include routers, authentication servers, and management systems in regular threat

The Fire Ant campaign demonstrates the risk of compromising trusted network infrastructure rather than directly targeting endpoints. Organizations should treat routers, authentication servers, and management systems as critical security assets and monitor them for unauthorized changes and persistent access.