China-Linked Hackers Turn Cisco Routers Into Covert Attack Infrastructure
17 Articles
17 Articles
China-linked hackers turn Cisco routers into covert attack infrastructure
A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia. The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR routers in 2026, using them to collect network traffic while suppressing evidence of its activity. The attackers…
SCIENCE & TECH: Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it’s all thanks to this new malware
Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts Compromised routers act as operational platforms Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is ac…
Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware
Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones.
China-linked Fire Ant uses Cisco routers for credential theft and log suppression
A China-linked intrusion set tracked as Fire Ant was reported exploiting Cisco routers to steal credentials and interfere with security logging, turning edge network devices into collection and concealment points. The activity is detailed in...
The Fire Ant group, linked to China, installs a permanent listening device on Cisco iOS XR routers placed at the heart of corporate networks. These compromised devices collect traffic and technical team IDs, without triggering any alert. The operation is in line with a campaign launched in 2025 against VMware hypervisors.
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium













