OTSecurity

Sygnia highlights Fire Ant risks from compromised routers, authentication systems in critical infrastructure


New research from cybersecurity firm Sygnia detailed that threat actor known as Fire Ant expanded its operations from hypervisor-level compromises into trusted infrastructure, targeting routers, authentication systems and Linux management hosts to maintain covert access and reach connected high-value environments and critical infrastructure installations. First reported in 2025, Fire Ant remained active into 2026, with Sygnia finding that the actor compromised Cisco IOS XR routers, TACACS authentication infrastructure and Linux management systems, turning them into operational platforms for traffic collection, credential theft, persistence and movement into connected networks, including environments associated with critical infrastructure.

Sygnia identified in a blog post that Fire Ant’s latest activity shows a shift toward compromising the infrastructure that controls how environments connect, authenticate administrators and record activity. The group used compromised routers for covert connectivity, traffic collection, command-output manipulation and logging suppression, while targeting TACACS (Terminal Access Controller Access-Control System) servers to intercept authentication flows and collect credentials. On Linux management hosts, Fire Ant deployed long-lived implants and backdoors, some dating to 2025 and reused in 2026. 

Sygnia said the activity also involved manipulating telemetry and other evidence sources, meaning defenders could not rely on a single source of logs or forensic data to reconstruct the intrusion. Furthermore, the hacker deployed long-lived implants across Linux management infrastructure, including Medusa-related components, custom SSH backdoors, Zabbix-masquerading malware, and packet-triggered backdoors.

Clearly, across routers, TACACS servers, and Linux hosts, the actor modified or bypassed telemetry sources defenders normally rely on, reinforcing the need to validate logs against memory, disk, network, authentication, and configuration evidence. “By compromising routers, authentication systems, and Linux management hosts, Fire Ant gained strategic positions from which it could collect traffic and credentials, maintain covert access, and explore paths toward connected high-value environments, including critical infrastructure. The compromise therefore had implications beyond the systems directly affected.”

Unlike previous Fire Ant activity, the recent activity appeared to use the compromised environment as an infrastructure platform from which it could explore reachability into connected high-value networks, including critical infrastructure.  “In this model, routers, TACACS servers and jump hosts are not peripheral assets. They are the path to the target behind the target.”

For defenders, this distinction is critical since a narrow investigation risks missing operational objectives, while treating network and management infrastructure as a trusted layer expands scope to connected routes, administrative paths, shared authentication, and segmentation controls.

The hackers also manipulated evidence sources defenders depend on. It suppressed router logging, altered command output, captured administrative credentials, tampered with host logs, and deployed multiple persistent backdoors. As a result, investigators could not rely on any single telemetry source to accurately reconstruct the activity.

The post added that the key implication for organizations is that routers, authentication servers, hypervisors, jump hosts, and management appliances must be treated as first-class security and forensic assets. These systems require the same level of monitoring, hardening, and incident-response readiness as traditional endpoints and servers. When trusted infrastructure is compromised, an attacker can gain a path into connected environments and ability to obscure how that access was used.

Sygnia detailed that components show that Fire Ant treated routers as operational platforms. “The actor built capabilities for persistence, outbound communication, syslog suppression, and command-output manipulation. In a highly interconnected environment, this level of router control is strategically significant: a compromised edge router can become a vantage point for covert connectivity, traffic observation, and access to connected networks, including critical infrastructure environments that rely on trusted routing and management paths.”

From a threat intelligence perspective, the post added that this also clarifies the likely objective behind the activity. “In a highly interconnected environment, routers, TACACS servers, virtualization platforms, and Linux management hosts are not only internal systems; they are part of the trusted infrastructure layer that connects, authenticates, and manages access across connected networks. Compromising this layer can provide an actor with more than just persistence inside the immediate victim. It can create a bridge toward other high-value environments, including critical infrastructure that depends on trusted routing, authentication and management relationships.”

By compromising infrastructure that routes traffic, authenticates administrators, manages access, and records activity, Fire Ant turned the environment into a potential access path toward connected high-value networks, including critical infrastructure. This position allowed the actor to explore reachability beyond the initially compromised environment while also weakening the evidence sources defenders rely on to understand what happened.

“The central lesson is that defenders must protect more than the systems that store sensitive data,” the Sygnia post identified. “They must protect the infrastructure that makes other systems reachable, trusted, and observable. When that layer is compromised, the impact extends beyond a single organization: the actor may gain a vantage point for collection, a path toward connected targets, and the ability to make trusted infrastructure tell an incomplete story.”

The post identified that Fire Ant’s activity aligns with infrastructure-focused espionage tradecraft. Mandiant and Google Cloud have identified UNC3886, a China-nexus espionage cluster, as targeting the same infrastructure landscape covering virtualization platforms, edge devices, and network infrastructure. Sygnia assesses that Fire Ant operations substantially mirror this publicly reported activity.

“The overlap is strongest at the level of durable behavior. Public reporting has described VMCI-based backdoors, TACACS credential theft, Medusa-rootkit usage, custom SSH access, and router-focused operations,” according to the post. “Sygnia’s 2026 observations contain the same operational themes: virtualization-adjacent access, credential capture from authentication infrastructure, Linux rootkits, custom SSH backdoors, router compromise, and deliberate telemetry suppression.”

It noted that the differences are also important. “Several filenames, paths and deployment details differ from public reporting. This should not be treated as a contradiction. For mature actors, atomic indicators often change after exposure, while the operating model remains stable. In this case, the stronger correlation comes from how the actor uses infrastructure, not from whether every path or filename matches a previous report.”

Sygnia’s observations extend the model into a highly interconnected environment where routers, TACACS servers, and Linux management hosts were used as part of a broader access and collection layer. This reinforces the view that Fire Ant/UNC3886-like operations are not endpoint-centric campaigns. They are infrastructure-control-plane campaigns.



Source link