news.mlab.sh
Back to the feed
threat-intel

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

High
Summary

A recent report by Sygnia details the ‘Fire Ant’ campaign, a sophisticated operation led by Chinese hackers utilizing compromised Cisco routers as a platform to monitor organizations, steal credentials, and expand access to other networks. The campaign, linked to Google’s Mandiant unit (UNC3886), demonstrates a shift in tactics – moving beyond endpoint attacks to targeting critical infrastructure components like routers and hypervisors to establish long-term, covert access. This represents an evolution in Chinese state-backed espionage targeting network infrastructure, requiring a fundamental shift in how security teams approach trust relationships across their environments.

A recent report by cybersecurity firm Sygnia has highlighted a sustained and evolving hacking campaign dubbed ‘Fire Ant,’ orchestrated by China-based attackers. The campaign leverages compromised Cisco routers as a central platform for extensive reconnaissance and intrusion activities. Sygnia researchers noted that ‘Fire Ant’ overlaps with a group previously linked to Google’s Mandiant unit (UNC3886), which was implicated in attacks on prominent strategic organizations between 2022 and 2024.

Sygnia’s investigation revealed that the attackers are no longer solely focused on endpoint attacks. Instead, they are strategically targeting routers, hypervisors, and other infrastructure components – such as Linux management hosts – to gain a broader perspective of an organization’s network and establish durable access. The campaign has been active since 2025 and continued into 2026, with 2026 compromises impacting both victims and third-party environments, exploiting infrastructure relationships to breach high-value networks and critical infrastructure.

The attackers are adept at manipulating evidence and concealing their activity, including deleting files and tampering with firewall rules. A key element of their strategy involves compromising TACACS servers, which serve as administrative checkpoints, to harvest credentials and observe administrative activity. This allows them to build a comprehensive understanding of user behavior and create ambiguity between legitimate accounts and malicious activity.

Sygnia warned that routers, hypervisors, and similar infrastructure components should be treated as ‘first-class’ security forensic assets, requiring continuous monitoring, hardening, and incident response readiness. The campaign echoes previous efforts by Chinese state-backed groups targeting Cisco firewalls and routers, including the Salt Typhoon and Volt Typhoon campaigns.

Experts emphasize the significance of Sygnia’s findings due to the attackers’ deliberate efforts to remain invisible to traditional security tools, targeting devices often outside the scope of security monitoring. This pattern of long-dwell, infrastructure-level access aligns with broader trends in Chinese espionage targeting telecom and network infrastructure, advocating for continuous validation of trust relationships across management infrastructure rather than periodic checks.

Read the full article at The Record