
Sygnia found attempts to suppress logging and conceal configuration activity on affected network equipment, while evidence was also tampered with on compromised Linux systems.
The firm described the operation as creating a potential “target behind the target” scenario, in which access to one organization’s trusted infrastructure could expose paths toward other high-value environments. Sygnia said Fire Ant probed systems associated with critical infrastructure, although the report does not establish that the critical-infrastructure systems being probed were successfully compromised.
Sygnia assesses that Fire Ant’s activity strongly overlaps with publicly reported operations attributed to UNC3886, a China-nexus espionage cluster tracked by Mandiant, but has not treated the two as definitively identical. Mandiant has previously documented UNC3886 targeting network equipment and TACACS infrastructure while attempting to evade conventional monitoring.
