China-Linked 'Fire Ant' Group Targets Cisco Routers to Steal Credentials and Cover Its Tracks
Security researchers at Sygnia have identified an expanded campaign by a China-nexus cyber espionage group tracked as Fire Ant, which has moved beyond its earlier focus on VMware hypervisors to target Cisco IOS XR routers, TACACS authentication servers, and Linux systems used to manage critical network infrastructure.
These systems are attractive targets because they sit at the heart of how organisations route traffic and verify user identity. By compromising routers and authentication servers, attackers can potentially steal login credentials, move laterally through a network, and interfere with security logging to hide their activity from defenders. This makes detection significantly harder, as the very systems meant to record suspicious behaviour may be manipulated or blinded.
While this campaign has been linked to sophisticated, state-associated actors typically targeting large enterprises, the techniques used—exploiting weaknesses in network infrastructure and authentication systems—are broadly applicable and could inspire similar attacks against smaller organisations with less mature defences. Any business relying on network routers, VPNs, or centralised authentication systems should treat this as a reminder to review how well those systems are patched, monitored, and segmented from the rest of the network.