When attackers gain control not over a separate server, but over systems that the entire network trusts, the usual logs and access rules cease to be a reliable support. Sygnia revealed a new phase of Operation Fire Ant: in 2026, the China-affiliated cluster went beyond VMware and attacked Cisco IOS XR routers, TACACS servers, and Linux administration hosts.
In 2025, the Fire Ant was fixed primarily in VMware ESXi and vCenter, using hypervisors as a hidden access point to virtual machines. The new campaign maintained the same principle, but moved it to the network level. Sygnia discovered specialized components for IOS XR, which suppressed system logs, changed team output, and maintained hidden connections to external infrastructure.
The investigation began with an unusual GRE tunnel on the Cisco router. The interface worked, although it was neither in the current configuration nor in the history of change. The tunnel led to the old Linux server, from where Fire Ant checked the availability of systems in connected networks. On the host worked BridgeAgent, disguised as agent Zabbix and able to launch additional tools and reverse shell.
A separate target was TACACS+ servers, which centrally check the administrators of network equipment and record their actions. The malicious TacTap set implemented the library directly into the tac_plus process, intercepted active sessions, and stored credentials in a hidden file. The compromise of such a node allowed not only to steal passwords, but also questioned the authenticity of access logs.
On Linux control hosts, Fire Ant left several ways to return to the network: Medusa rootkit, its own SSH backdoors, masquerading as system services programs and backdoors that woke up after a special network package. Some of the components appeared in 2025 and were used in 2026. The attackers also disabled SELinux, changed iptables and ruled logs of entrances.
Sygnia believes that the Fire Ant methods overlap strongly with the activity of the Chinese spy cluster UNC3886, but relies primarily on the similarity of tactics and tools. Defenders are advised to separately control routers, TACACS servers, hypervisors and jump hosts, look for unexpected tunnels and processes, and logs to check with network telemetry, memory, disk and device configuration.
In 2025, the Fire Ant was fixed primarily in VMware ESXi and vCenter, using hypervisors as a hidden access point to virtual machines. The new campaign maintained the same principle, but moved it to the network level. Sygnia discovered specialized components for IOS XR, which suppressed system logs, changed team output, and maintained hidden connections to external infrastructure.
The investigation began with an unusual GRE tunnel on the Cisco router. The interface worked, although it was neither in the current configuration nor in the history of change. The tunnel led to the old Linux server, from where Fire Ant checked the availability of systems in connected networks. On the host worked BridgeAgent, disguised as agent Zabbix and able to launch additional tools and reverse shell.
A separate target was TACACS+ servers, which centrally check the administrators of network equipment and record their actions. The malicious TacTap set implemented the library directly into the tac_plus process, intercepted active sessions, and stored credentials in a hidden file. The compromise of such a node allowed not only to steal passwords, but also questioned the authenticity of access logs.
On Linux control hosts, Fire Ant left several ways to return to the network: Medusa rootkit, its own SSH backdoors, masquerading as system services programs and backdoors that woke up after a special network package. Some of the components appeared in 2025 and were used in 2026. The attackers also disabled SELinux, changed iptables and ruled logs of entrances.
Sygnia believes that the Fire Ant methods overlap strongly with the activity of the Chinese spy cluster UNC3886, but relies primarily on the similarity of tactics and tools. Defenders are advised to separately control routers, TACACS servers, hypervisors and jump hosts, look for unexpected tunnels and processes, and logs to check with network telemetry, memory, disk and device configuration.