Fire Ant Migrates from VMware Hypervisors to Cisco IOS XR Routers and Transforms TACACS into Credential Collector

Sygnia detailed on August 30 how the Chinese espionage cluster Fire Ant, with significant overlap with UNC3886, has transitioned from the virtualization layer to Cisco IOS XR routers and TACACS servers for high-value clients.
Incident response firm Sygnia released an investigation on August 30 regarding the ongoing activities of the Chinese espionage cluster tracked as Fire Ant, which has now moved from VMware virtualization layers, its traditional target, to Cisco IOS XR routers, TACACS servers, and management Linux hosts. The analysis attributes significant overlap to UNC3886, a grouping documented by Mandiant and Google Cloud that focuses on virtualization platforms, edge devices, and network infrastructure.
The starting point of the investigation was an innocuous anomaly: an active Generic Routing Encapsulation tunnel on a Cisco IOS XR router with no running configuration and no commit history to explain its creation. The Sygnia team then traced a complete chain of persistence hidden in a false system service, which executes the implant only during alternate hours to reduce the detection surface, and a selective syslog message suppression routine to hide tunnel traffic from legitimate administrators.
Two New Tools in the Chain
The investigation identified two unprecedented artifacts. The BridgeAgent is a persistent tunneling implant that masquerades as zabbix_agent.service, a systemd unit familiar to infrastructure teams that rarely appears on EDR radars. The TacTap is a credential collection toolkit focused on TACACS, featuring library injection and Unix socket file descriptor handoff to capture administrative authentications in transit. Combined, these tools enable Fire Ant to collect privileged credentials, move laterally between segments, and reduce trust in the audit logs themselves.
The choice of the network layer is not random. IOS XR routers and TACACS appliances rarely have detection agents, fall outside the scope of several SIEM tools, and concentrate the traffic that the attacker wants to inspect. Fire Ant's movement to this layer renders standard corporate endpoint detection policies nearly useless.
Where the Attack Materializes Outside China
The geographic reach is the most concerning aspect. Cisco IOS XR is used as a backbone by carriers such as NTT and KDDI in Japan, Deutsche Telekom in Germany, various tier-1 providers in the U.S., and telecommunications in emerging markets that serve as transit for regional traffic. Sygnia observed connection attempts against critical infrastructure environments, without confirmation of effective compromise in these targets, but the reconnaissance pattern is consistent with persistent access preparation.
The immediate takeaway for the global financial sector is clear. TACACS remains standard in connectivity environments between data centers of major banks, and the same technique of publicly unconfigured tunneling fits typical MPLS segmentation environments of exchanges and clearinghouses. According to Sygnia itself, the adversary demonstrates operational tradecraft compatible with sustained espionage, rather than opportunistic movement, which broadens the potential dwell time horizon.
What Network Teams Need to Validate Now
The first practical validation is to hunt for GRE tunnel interfaces without entries in running-config and corresponding commit history, following the indicators published by Sygnia. The second is to review the integrity of TACACS hosts, with attention to injected libraries and atypical local sockets. The third, and less comfortable, is to accept that any administrative credentials used on compromised routers in recent months should be considered exposed and rotated. Fire Ant has made it clear that when the log is deleted on the very device that generates the log, the only remaining defense is out-of-band telemetry, something that most environments still do not have.
This incident also shifts the contractual discussion with telecom and managed network providers. Questions like "What is your out-of-band log collection policy on IOS XR" and "How do you ensure TACACS integrity against library injection" now weigh more in RFPs than the traditional compliance checklist. Sygnia did not make a conclusive attribution, but the technical pattern converges with UNC3886, and that is enough to reorder defense priorities in any globally distributed operation.