Compromising a server can expose one machine. Compromising the right router can give attackers visibility into an entire network.
Security firm Sygnia says the China-linked Fire Ant threat actor compromised Cisco IOS XR routers and used its privileged access to monitor network traffic and establish covert connections into surrounding environments.
According to Sygnia, the China-nexus actor also compromised Linux management hosts and the Terminal Access Controller Access-Control System (TACACS), enabling unauthorized access to authentication systems.
Sygnia said its investigation found evidence of scanning and connection attempts toward high-value environments, including systems associated with critical infrastructure. The apparent objective was to use the compromised trusted infrastructure as a bridge toward other environments — a strategy Sygnia describes as targeting the “target behind the target.”
How Fire Ant turned the router into a foothold
According to Sygnia, the attackers had hidden evidence of their activity from the router’s commit logs. But when investigators found an active Generic Routing Encapsulation (GRE) tunnel with no corresponding record, the discrepancy prompted a deeper examination of the Cisco IOS XR router.
That examination showed that Fire Ant had gained privileged access to the router and was using it to monitor network traffic.
The activity eventually led investigators to the organization’s TACACS authentication infrastructure, where they discovered that Fire Ant had compromised these servers and deployed TacTap — their malicious toolset.

That gave the attackers another valuable source of access: administrator credentials and authentication sessions that could potentially be used against other network devices. Alongside the router compromise, Fire Ant maintained several persistence mechanisms on Linux management systems, giving it multiple ways to regain access if individual implants were discovered and removed.
Taken together, the sequence shows that the router was not the end goal. Fire Ant was simply using it as a launch pad to expand its broader aims.
Why routers?
A router sits at a point where large amounts of network traffic pass through, connects different parts of an organization’s infrastructure, and can provide a useful vantage point for discovering what else is reachable from inside the network.
That makes a compromised router considerably more valuable than an ordinary endpoint.
The choice also fits with Fire Ant’s broader pattern of targeting infrastructure that sits between an attacker and the systems they ultimately want to reach.
After previously targeting VMware virtualization environments, the actor is now demonstrating that routers and authentication systems can provide another route to the same objective: gaining a trusted position from which it can see, access, and move toward other environments.
Sygnia identifies Fire Ant as a China-nexus actor whose activities overlap with those linked to UNC3886. U.S. officials have also warned of foreign-made routers, indicating that compromised routers can be used for surveillance, data theft, and access to other networks.
What a router compromise means for users
The Fire Ant campaign shows why routers and management infrastructure cannot be treated as background equipment. Once attackers gain privileged access to those systems, they may be able to observe traffic, reach other network segments, and capture credentials that extend the intrusion well beyond the original device.
The discovery of an active GRE tunnel that did not appear in the router’s commit logs is particularly important. It shows why defenders may need to compare a device’s current state with its expected configuration rather than relying entirely on conventional logs.
The larger lesson is that removing one malicious implant may not end an intrusion. Fire Ant maintained access across routers, Linux management hosts, and authentication infrastructure, giving defenders multiple layers to investigate before they can be confident the attacker is gone.
More News: Scammers are impersonating Indeed recruiters and directing job seekers to fake Android interview apps that install spyware, abuse Accessibility permissions, and can make themselves difficult to remove.





