Fire Ant Pivots to Cisco Routers, Deploys 'BridgeAgent' Backdoor for Traffic Collection
Summary
Incident-response firm Sygnia documented the China-linked Fire Ant cluster shifting from VMware hypervisors to compromising Cisco IOS XR routers, TACACS authentication servers and Linux management hosts in August 2026.
Details
Sygnia found an active GRE tunnel interface on a Cisco IOS XR router that no running configuration or commit history could explain. The attackers installed custom malware persisting through a fake system service that runs only during alternating hours, selectively suppressed syslog messages, established outbound Telnet connections to Fire Ant infrastructure, and provided logging-free interactive shell access.
The group captured traffic from multiple routers and uploaded PCAP files to external FTP servers, using a compromised router as a covert vantage point on trusted network paths to probe connected critical-infrastructure environments over SSH, SMB/RPC and RDP. Sygnia dubbed this "target behind the target". A newly documented backdoor, BridgeAgent, disguises itself as a legitimate Zabbix monitoring agent, persists as a root systemd service and supports TLS reverse shells.
Assessment
The activity strongly overlaps Google's UNC3886, with differences in filenames, paths and implementation details. Fire Ant systematically tampers with system logs and file timestamps, so evidence recovered from compromised infrastructure must be validated against independent sources. The pivot to routing and authentication infrastructure signals a strategic shift toward trusted-path traffic collection rather than endpoint dwell.