Cisco Systems IncFire Ant exploits Cisco IOS XR routers, potentially harming Cisco's product reputation and demand.

Sygnia, a global cyber readiness and response firm, has released findings on ongoing espionage activity by a China-nexus threat actor tracked as Fire Ant, which is targeting routers, authentication systems, and Linux management hosts to collect intelligence and explore paths toward connected high-value environments. The 2026 activity marks an evolution from Fire Ant's 2025 focus on VMware ESXi and vCenter virtualization infrastructure to strategic abuse of trusted infrastructure, including Cisco IOS XR routers used as operational platforms to suppress evidence, collect traffic and credentials, and expand access. The investigation uncovered two novel tools: BridgeAgent, a masquerading implant for tunnelling and persistence, and TacTap, a TACACS credential-collection toolset. Fire Ant also established resilient persistence through long-lived implants, manipulated logs and firewall rules, and disabled SELinux on Linux systems. Sygnia's findings highlight a campaign targeting interconnected environments where routers, TACACS servers, and Linux hosts serve as a broader access and collection layer, potentially enabling visibility and access beyond the immediate victim.
Cisco Systems IncFire Ant exploits Cisco IOS XR routers, potentially harming Cisco's product reputation and demand.