The router stopped just moving traffic
Sygnia researchers disclosed on August 31 a campaign attributed to Fire Ant, a Chinese espionage group with what the firm describes as strong operational overlap with UNC3886, a threat actor Google's Mandiant unit has tracked in prior campaigns against network edge devices, though Sygnia notes the implementation details differ enough to treat this as a distinct operation rather than a simple rebrand. The group compromised Cisco IOS XR routers, TACACS authentication servers used to control administrative access, and Linux hosts used for network management, giving it a foothold across the layers that most enterprises assume are separately defended.
The detail that separates this campaign from routine router compromise is an undocumented GRE tunnel interface researchers found configured on affected devices with no corresponding entry in the router's visible configuration. A generic routing encapsulation tunnel of this kind lets an attacker move traffic through a device in a way that standard configuration exports and audits simply do not surface, because the interface exists at a level most review processes never inspect directly.
Built to survive the log review that should have caught it
Fire Ant paired the tunnel with a custom malware component that ran fake system services on an alternating schedule, making process listings look unremarkable to an administrator doing a quick manual check. The group selectively suppressed syslog entries tied specifically to tunnel activity, meaning a defender pulling logs for a routine audit would see an apparently clean history even while the tunnel remained active and in use for command traffic.
On top of the tunnel and log suppression, researchers identified a backdoor Sygnia calls BridgeAgent, deliberately disguised as a legitimate Zabbix monitoring agent, the kind of process an operations team would expect to see running and would be unlikely to flag for removal. Combined with root-level systemd persistence mechanisms and outbound Telnet connections to attacker-controlled infrastructure, the toolset was built specifically to survive the exact review steps most enterprise network teams rely on as their primary detection method.
From transit device to collection platform
Sygnia's research frames the core shift plainly: this behavior moves a router's role from a transit device to a collection platform. Once a router carries this kind of persistent, hidden tunnel, it becomes a vantage point from which an attacker can capture packet data traversing the network, upload it to external infrastructure, and use the device for reconnaissance across everything connected downstream, all without touching a single endpoint that traditional detection tools are watching.
That reframing matters because most enterprise security programs invest heavily in endpoint detection and response while treating core network infrastructure, routers, switches, and authentication servers, as a comparatively static, trusted layer that gets patched on a schedule rather than monitored continuously for behavioral anomalies. Fire Ant's campaign is a direct exploit of that asymmetry in security investment, targeting exactly the layer least likely to have active threat hunting pointed at it.
Interactive access without a trace
Beyond passive collection, Sygnia documented interactive shell access on compromised devices that left no meaningful logging trail, alongside TLS reverse shells that blend outbound command and control traffic with legitimate encrypted network traffic passing through the same interfaces every other application uses. That combination gives Fire Ant hands on keyboard access to core network infrastructure whenever it chooses to use it, not merely a passive tap collecting data quietly in the background while defenders go about routine operations unaware anything has changed on the device.
For a network engineering or security operations team, interactive access without logging means that even a well-resourced incident response effort cannot simply pull router logs and trust the resulting timeline as an accurate account of what happened and when. Sygnia's guidance reflects this directly, warning that any logs recovered from a device suspected of compromise in this campaign need independent validation against alternative data sources, such as network flow records captured elsewhere, rather than being taken as a reliable record on their own.
What Sygnia is telling defenders to do
Sygnia has published indicators of compromise, YARA detection rules, and hunting methodologies specifically built around this campaign's tradecraft, giving network security teams a concrete starting point rather than a general warning to be more careful. The core recommendation is to treat network edge and management infrastructure as an active hunting target in its own right, not a category that gets a clean bill of health simply because a configuration export looks normal during a scheduled review.
Practically, that means validating router configurations against out of band baselines captured through independent tooling, not just the device's own reported configuration, and treating any unexplained GRE or tunnel interface as an incident until proven otherwise rather than a benign artifact of legacy configuration. It also means auditing whether TACACS authentication infrastructure itself, the system meant to control who can administer these routers in the first place, has been validated as uncompromised.
The roadmap question for enterprise network teams
Every enterprise running Cisco IOS XR routers, or comparable core network infrastructure from any vendor, should treat this disclosure as a prompt to check whether network security monitoring extends meaningfully below the endpoint layer, into the routers and authentication systems that sit underneath everything else. Most security operations centers are tuned to watch identity providers, cloud workloads, and endpoints, with core network gear treated as infrastructure to be patched rather than infrastructure to be actively hunted on.
Fire Ant's campaign is a reminder that nation-state actors are willing to invest heavily in tradecraft specifically designed to exploit that gap in monitoring attention, using log suppression, disguised backdoors, and undocumented tunnels engineered to survive exactly the review processes most organizations already have in place today. Closing that gap means budgeting for network infrastructure monitoring as a distinct discipline with its own tooling and headcount, not an afterthought bolted onto an existing endpoint security program that was never designed to look at routers in the first place.



