A sophisticated China-nexus actor is abusing routers using the Cisco IOS XR operating system in an espionage campaign that reaches into high-value networks and critical infrastructure, according to a report released Sunday by Sygnia.
The actor, tracked as Fire Ant, gained wide recognition in 2025 after abusing VMware environments. Researchers said this new campaign represents a further expansion into trusted network environments.
“The observed activity is most consistent with long-term espionage,” Asaf Perlman, director of incident response at Sygnia, told Cybersecurity Dive. “Fire Ant collected network traffic and administrative credentials, mapped routes and trusted relationships, established multiple persistent access mechanisms and manipulated evidence to reduce the likelihood of detection.”
Cisco devices have been a frequent target of sophisticated threat groups in recent years, in part because these devices can provide trusted access to organizations.
Unusual activity
Sygnia’s investigation began after unusual activity was observed in a Cisco IOS XR router, Perlman said. Researchers said a generic routing encapsulation tunnel interface was operational, even though a running configuration and the commit history could not explain how it was created.
“This indicated that the device’s operational state and the evidence available to administrators might no longer be reliable,” Perlman said.
The attackers compromised an access choke point called a Terminal Access Controller Access Control Point (TACACS) in order to interfere with the authentication process and steal credentials.
The investigation uncovered novel attack tools, including a Zabbix-masquerading implant for tunneling and persistence, which researchers call BridgeAgent. Zabbix is normally an open-source monitoring tool, but this implant was used as a backdoor by hackers.
A second tool, dubbed TacTap, was used for gathering credentials.
Perlman declined to provide details on the location or industry of the targeted organization, citing the need to protect the victim and the environments of other connected systems.
The investigation extended beyond the unusual router activity, leading to compromised Linux infrastructure, additional network activity and the discovery of long-term persistence mechanism, among other issues.
Mitigation measures
Perlman says there are several steps that security teams should take to harden their environments:
- Restrict privileged access to network and management infrastructure using dedicated administrative paths.
- Monitor for unexpected generic routing encapsulation or tunnel interfaces any discrepancies between operational state and visible configuration.
- Centralize router authentication and network telemetry outside of managed devices, so evidence on a compromised system cannot be easily manipulated.
Sygnia previously tracked the 2025 Fire Ant espionage campaign targeting VMware ESXi and vCenter environments. The activity overlapped with research from Mandiant, which tracked espionage activity by the China-nexus group UNC3886.
UNC3886 previously targeted Juniper MX routers using custom backdoors as part of a wider espionage effort.
A spokesperson for Cisco was not immediately available for comment.
