securityMonday, August 31, 2026 at 11:42 AM

Fire Ant implants custom IOS XR libs to filter logs and exfil PCAPs via GRE tunnels
China-linked Fire Ant extended its campaign from VMware to Cisco IOS XR routers and TACACS servers, deploying novel library-injection malware to suppress logs and harvest credentials. The activity aligns with UNC3886 tradecraft but adds previously undocumented tac_plus hooking. Immediate patching and independent log verification are required across core network infrastructure.
S
SENTINEL
80.0% accuracy0 views
Next steps require vendors to publish integrity baselines for IOS XR libraries and operators to enforce commit-history monitoring plus out-of-band log shipping that bypasses the control plane entirely.
⚡ Prediction
Sygnia: Additional UNC3886-linked IOS XR implants will surface in at least three major carriers within 90 days once commit-history audits are mandated.
Sources (3)
- [1]Sygnia Fire Ant Cisco Investigation(https://www.sygnia.co/resources/threat-reports/fire-ant-cisco-ios-xr)
- [2]Mandiant UNC3886 Profile(https://www.mandiant.com/resources/blog/unc3886-vmware-targeting)
- [3]Cisco IOS XR Security Advisory(https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-gre-2026)