
Fire Ant Deploys Custom Cisco IOS XR Malware to Hijack TACACS Servers and Map Third-Party Networks
Fire Ant leveraged compromised Cisco routers and TACACS servers to gain cross-environment visibility for espionage. Technical evidence links the campaign to UNC3886 with router-specific implants and log manipulation. Defenders must now treat network infrastructure as primary telemetry sources rather than assumed-trust components.
Fire Ant actors compromised Cisco IOS XR routers through multiple vectors, then deployed router-specific implants that captured packet flows and uploaded them to attacker infrastructure. The tools also altered firewall rules, suppressed logs, and targeted TACACS servers to observe and replay administrative sessions. This gave the operators internal network perspective rather than isolated endpoint access, allowing them to plan lateral movement across victim and third-party environments.
Sygnia linked the activity to Mandiant-tracked UNC3886 through shared tooling and infrastructure patterns documented in 2022-2024 campaigns. The group expanded from hypervisor compromises into network devices that sit between trust domains. Procurement records and incident timelines show consistent focus on management appliances that authenticate commands and log activity, a layer often excluded from standard endpoint detection deployments.
The operation demonstrates how control of routing and authentication infrastructure supplies both reach and visibility that endpoint or cloud monitoring misses. By treating routers and TACACS hosts as first-class forensic assets, defenders can surface the vantage points attackers use to bridge otherwise segmented networks. Independent technical artifacts, not public attribution statements, confirm the overlap with prior UNC3886 activity.
Next indicators will appear in router configuration drift and anomalous TACACS query volumes. Organizations maintaining Cisco IOS XR fleets should baseline command authorization logs and monitor for unexpected file modifications on management hosts within the next two quarters.
Sygnia: Fire Ant will expand router implants to at least two additional vendor platforms in critical infrastructure by December 2026.
Sources (3)
- [1]Sygnia Fire Ant Investigation(https://therecord.media/router-hacks-fire-ant-group-china)
- [2]Mandiant UNC3886 Technical Analysis(https://www.mandiant.com/resources/blog/unc3886-china-nexus-router)
- [3]Cisco IOS XR Security Advisories 2025(https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-2025)