← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 1, 2026 · 09:44via CSO Online

China-linked hackers turn Cisco routers into covert attack infrastructure

Brief

A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia .

The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR routers in 2026, using them to collect network traffic while suppressing evidence of its activity. The attackers also compromised TACACS authentication infrastructure and Linux management hosts as they explored access to connected high-value environments.

The findings build on Sygnia research published last year that documented Fire Ant establishing deep persistence in VMware ESXi and vCenter environments. The latest activity shows the group extending that approach into infrastructure used to route traffic and administer enterprise networks.

Read more on CSO Online