Fire Ant: China-nexus actor hijacks Cisco IOS XR, TACACS (TacTap) and Linux management hosts
Sygnia's 30 August 2026 report (The Hacker News 31 August) says Fire Ant, first reported in 2025 and assessed to overlap UNC3886, remained active into 2026 and expanded from hypervisors into trusted infrastructure: Cisco IOS XR routers, TACACS authentication, and Linux management hosts. Router implants (including a masqueraded grub-rommon service launching /usr/bin/acpid) suppressed selected syslog, hid CLI output, and supported GRE tunnels. On the tunnel far-end, BridgeAgent persisted as zabbix_agent.service (filename zabbix_agent, not the legitimate zabbix_agentd) โ a Zabbix-name masquerade, not a Zabbix product CVE. TacTap injects /lib/libseconfd.so into tac_plus to steal credentials to /var/log/.tacplus.acct (XOR 0xEF). Sygnia also describes Medusa-related Linux access, custom SSH backdoors, and REPTILE-like packet-triggered implants. Treat routers, TACACS and jump hosts as first-class forensic assets. Primary: Sygnia.
- Product
- Cisco IOS XR routers, TACACS (tac_plus), Linux management hosts
- Versions
- n/a (campaign / implant set; not a vendor CVE card)
- Exploited in Australia?
- unknown
- Patch to
- Hunt unexpected GRE/tunnels, tac_plus injection, zabbix_agent.service that is not a real Zabbix agent, and Medusa/custom SSH paths in Sygnia's IoC table
Primary: Sygnia (30 Aug 2026) ยท Vendor: The Hacker News (31 Aug; secondary)
