Tuesday, 1 September 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware

TechRadar ·
Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware

Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts Compromised routers act as operational platforms Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts.

This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers.

Once they compromise a router , they don’t just use it to move around the network, the researchers explained.

Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars.

For authentication systems, Fire Ant was seen taking aim at TACACS servers.

Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well.

Finally, Sygnia says Fire Ant also targets Linux management hosts.

The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of malware spoofing legitimate software.

Target behind the target The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments.

Sygnia describes it as a “target behind the target” scenario: “This reinforces the “target behind the target” concept introduced earlier in this report.

Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim.

The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.

Very little is known about Fire Ant, besides the fact that it was first observed in 2025.

Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›