Fire Ant: Cisco IOS XR, TACACS, and Linux Management Infrastructure Hijacked into Spying and Access Platforms
1. Overview Title : Chinese Fire Ant hackers turn Cisco routers into spying platforms Publisher : BleepingComputer Publication Date : 2026-08-31 Original Source : BleepingComputer Related Sources : Sygnia Related Malware, Threat Groups, CVEs, Products : Fire Ant, BridgeAgent, TacTap, Medusa rootkit, Cisco IOS XR, TACACS+, Linux, Zabbix Severity : High 2. Executive Summary Fire Ant compromised Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The actors used GRE tunnels, suppressed logs and CLI outputs, captured network traffic, stole credentials, and deployed multiple long-term backdoors to explore connected high-value networks. 3. Attack Flow Turning Trusted Management Infrastructure into Relay Points Fire Ant gains high-privileged access to Cisco IOS XR routers and Linux management hosts. The initial access vector is not disclosed. The actors place persistence scripts and IOS XR-specific components on the routers, manipulating syslog and show outputs. They operate GRE tunnels with VRF and outbound Telnet connections that rarely appear in configurations or history logs. They capture network traffic into PCAP files on the routers and send them to external FTP servers to gather internal network topology and authentication flows. They deploy BridgeAgent, rootkits, custom SSH, and packet-triggered backdoors on the GRE-connected Linux hosts. They inject libraries into tac_plus using TacTap to harvest TACACS credentials. They probe connected SSH, HTTP(S), SMB/RPC, and RDP services to verify reachability to high-value networks, including critical infrastructure. 4. Threat Actor Positioning and Execution Environment External actors with high-privileged access to routers, TACACS servers, and Linux management hosts. The initial access vector is unknown. After the compromise, they explore connected target networks from inside organizational interconnections and management paths. 5. Visibility for Victims and Administrators Victims The activity r