The actor reaches BridgeAgent on the legacy Linux server | Image: Sygnia
At a Glance
- Actor: Fire Ant (suspected UNC3886 overlap)
- Activity Type: Espionage, network infrastructure breach, credential theft
- Targets: Edge routers, TACACS servers, Linux jump hosts
- Scale: Unknown number of connected critical infrastructure environments
- Jurisdiction: Unconfirmed (suspected China-nexus espionage group)
- Source: Sygnia Incident Response Report
TL;DR
The Fire Ant threat actor expanded its network operations significantly in 2026. The group aggressively targeted trusted infrastructure to breach connected high-value environments. Therefore, security teams must treat edge routers and management hosts as critical forensic assets.
What Happened
Sygnia researchers observed the Fire Ant threat actor breaching edge routers in 2026. The group moved beyond basic hypervisors to control the core infrastructure layer. Attackers compromised Cisco IOS XR routers to create operational platforms. These compromised platforms supported covert connectivity and malicious traffic collection. Furthermore, a detailed trusted infrastructure compromise allowed the group to intercept essential authentication flows.
The intruders heavily manipulated the evidence layer to hide their tracks. For instance, they altered command output and suppressed critical router logging. The attackers deployed a Zabbix-masquerading malware tracked as BridgeAgent. This backdoor facilitated periodic outbound polling to controller-supplied external servers. Additionally, they created anomalous GRE tunnels to extend their operational reach.
The attackers also targeted the vital systems managing administrative access. They deployed a specialized TACACS credential collection toolset known as TacTap. This multi-component mechanism maintained a malicious shared object inside the authentication daemon. Consequently, the malware intercepted accepted sessions and harvested sensitive credential data. The attackers encoded the stolen data using a simple single-byte XOR scheme.
The attackers utilized a raw packet-triggered remote access controller to maintain persistence. This malware actively listened on the network interface for specific TCP packets. Specifically, it monitored destination ports 443, 541, 8443, and 10443. It also watched for UDP packets sent from source port 40443. The intruders created an interactive shell and set the HISTFILE value to null. Consequently, this action completely disabled bash history logging for the threat actor. Analysts could not see the executed commands from the standard history file.
Who is Behind It
Security experts suspect a China-nexus espionage group operates these Fire Ant campaigns. Sygnia assesses that this recent activity strongly overlaps with public reporting on UNC3886. This attribution relies primarily on highly durable malicious behavior patterns. Notably, the threat actor used VMCI-based backdoors and custom SSH access tools.
The malware samples contained familiar magic strings used for backdoor activation. One binary searched raw network traffic for the “hpaVAj2FJ” kill marker. However, the exact deployment details differed slightly from past documented campaigns. These minor operational changes highlight a highly adaptable and capable adversary. Still, the overarching strategy remained entirely consistent with earlier UNC3886 cyber operations.
The group built a highly resilient access layer across Linux management hosts. They deployed custom SSH backdoors and Medusa-related rootkit components. Several Linux access tools remained fully operational from 2025 into 2026. The attackers disguised malicious files to match legitimate endpoint security software. They modified file timestamps to blend in with trusted system binaries. Even after deletion, these malicious processes remained active within system memory. Additionally, the intruders disabled SELinux to remove host-level security constraints.
Impact and Scale
This widespread compromise affected both direct and third-party administrative environments. The attackers successfully captured traffic from multiple compromised Cisco routers. Subsequently, they uploaded these packet captures directly to external FTP servers. The intruders also harvested sensitive passwords using their custom TACACS injector. By compromising routers, the attackers gained a strategic bridge into other networks.
This specific tactic is known as attacking the target behind the target. Network routers became valuable collection points for internal intelligence gathering. By gathering PCAP files, the attackers understood internal topology and routing relationships. The Sygnia report states, “The compromise therefore had implications beyond the systems directly affected.”
The group heavily modified firewall rules to sustain their unauthorized access. They redirected SSH traffic from selected internal sources to alternate local ports. Specifically, they routed traffic destined for port 22 directly to port 443. Furthermore, they enabled IPv4 packet forwarding on the compromised Linux management hosts. These unauthorized changes turned management hosts into dangerous covert tunneling nodes. This design provided an independent fallback channel that evaded standard host-level controls.
Sadly, the exact number of victims and financial damages remain unconfirmed claims today. However, the operational risk to interconnected critical infrastructure remains incredibly severe. The threat group positioned itself perfectly at the main administrative chokepoints. This allowed them to harvest credentials exactly as administrators used them. The attackers created serious ambiguity between legitimate account use and malicious activity.
What Comes Next and Protection Strategies
Organizations face a difficult challenge when trusted systems turn against them. Network defenders can no longer trust standard log files blindly. The report warns, “Investigators could not rely on any single source of telemetry to accurately reconstruct the activity.” Instead, security teams must validate logs against memory, disk, and network evidence.
Companies should immediately harden edge routers and core authentication servers. Moreover, incident response plans must specifically address these infrastructure layer threats. Administrators need to actively hunt for persistent backdoors and unauthorized configuration changes. Removing a single malicious binary will not eliminate this threat completely. Therefore, defenders must always assume that multiple access paths and stolen credentials exist.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!