← BACK TO FEED
TAG

china espionage1 article

Fire Ant Goes Deeper: China-Linked Hackers Hit Cisco Routers, TACACS Servers and Linux Hosts

A China-linked cyber espionage group called Fire Ant (strongly overlapping with UNC3886) has expanded its campaign to compromise Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts, turning them into credential-harvesting and network surveillance platforms. The attackers deployed custom malware to capture network traffic, steal authentication credentials via a novel library-injection technique, and actively suppress logs, security telemetry, and audit records to hinder detection and forensic investigation. The activity mirrors tactics attributed to Salt Typhoon in a separate CISA advisory, highlighting a broader Chinese espionage trend of targeting network infrastructure devices to gain persistent, privileged visibility into high-value networks.

1 Sept 2026