ThinkPatternGet the app
Story
TECHNOLOGY · SEP 3, 2026

China-Linked Fire Ant Group Compromises Cisco Routers

The Fire Ant cyberespionage group used TacTap malware to steal administrator credentials from Cisco routers to probe critical infrastructure networks.

A China-linked cyberespionage group known as Fire Ant compromised Cisco routers to steal administrator credentials and monitor network traffic. According to a report from cybersecurity firm Sygnia, the group deployed a tool called TacTap to embed malware within the Terminal Access Controller Access-Control System login verification process. This allowed the attackers to capture credentials during administrator sign-ins while suppressing router logs to hide their presence.

Sygnia described the group's strategy as targeting a "target behind the target," using the compromised routers as jumping-off points to probe other high-value networks, including critical infrastructure. The report did not identify a specific Cisco vulnerability used in the attacks, nor were any U.S. victims or affected countries publicly disclosed.

In response to internal testing, Cisco issued a security-hardening update for its IOS XR operating system on September 2 to address seven groups of vulnerabilities. The company did not mention Fire Ant in its advisory. The Cybersecurity & Infrastructure Security Agency declined to comment on the findings.


Reported across 2 outlets
Actors
Fire AntCisco Systems

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play