
Fire Ant Expands to Cisco Routers, Harvesting Credentials and Silencing Logs
A China-nexus cyber espionage group known as Fire Ant has moved beyond VMware exploits to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, turning routers into data-collection points that capture network traffic and credentials while suppressing logs and telemetry; the campaign shows evolving tradecraft with new tools like TacTap and BridgeAgent, overlaps with UNC3886 reporting, and underscores the need to treat routers and authentication infrastructure as critical forensic assets.