Chinese Espionage Group Fire Ant Targets Cisco Routers and Linux Management Systems
Cybersecurity firm Sygnia discovers the threat actor converting core network infrastructure into persistent surveillance platforms to access secondary targets.

A Chinese-linked cyberespionage collective known as Fire Ant has broadened its attack vector beyond virtualization environments to target enterprise routing gear, central authentication servers, and Linux administrative systems, according to recent findings from cybersecurity research firm Sygnia first reported by TechRadar Pro. The intrusion group was recently observed infiltrating Cisco IOS XR Routers to convert edge infrastructure into persistent surveillance posts.
Rather than using compromised routers merely as temporary transit points to navigate internal corporate networks, Fire Ant turns the network hardware into fully functional operational hubs. Once inside a router, the group captures passing network traffic, maintains external command-and-control links, and establishes deep operational visibility within trusted enterprise environments.
To maintain long-term access without alerting system administrators, the attackers modify standard operational behavior on the devices. The group manipulates command outputs generated by the router software and actively suppresses system logging mechanisms, allowing their malicious commands and data exfiltration activities to remain hidden from network security monitoring tools.
In addition to edge routers, Sygnia revealed that Fire Ant has targeted Terminal Access Controller Access-Control System (TACACS) authentication servers. Enterprise IT personnel rely on TACACS protocols to authenticate administrative logins across core hardware installations. By compromising these servers, the attackers are able to siphon administrative credentials and disrupt auditing mechanisms designed to record system access.
The threat actors have also focused on Linux management hosts, deploying persistent malware designed to guarantee ongoing access. Analysts identified multiple persistent backdoors installed on these hosts, including a specialized SSH backdoor alongside malicious software engineered to impersonate legitimate system binaries.
Researchers at Sygnia emphasized that these aggressive infrastructure compromises serve a broader strategic purpose, describing the campaign as a "target behind the target" model. Instead of viewing a single breached organization as the final endpoint, Fire Ant uses the victim's infrastructure to spy on and pivot into connected third-party networks that maintain implicit trust relationships with the compromised entity.
"This reinforces the "target behind the target" concept introduced earlier in this report. Fire Ant's interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments," Sygnia explained.
Public details regarding Fire Ant remain limited, with security analysts first documenting the cluster's activities in 2025. While several industry researchers have highlighted notable technical overlaps between Fire Ant and UNC3886—a Chinese espionage threat actor previously monitored by Google—analysts note that key operational differences currently prevent a definitive attribution linking the two groups.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


