China-Linked Hackers Hid in Cisco Routers, Stole Administrator Credentials: Report

By The Epoch Times | Created at 2026-09-03 09:46:35 | Updated at 2026-09-03 10:52:44 1 hour ago

A China-linked cyberespionage group compromised Cisco routers and hid its activity from the network administrators who managed them, cybersecurity firm Sygnia said in an Aug. 27 report.

The group also recorded traffic moving through the devices and used them to probe other high-value networks, according to the report.

The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment, allowing them to capture administrator credentials, Sygnia said.

Sygnia tracks the group as Fire Ant and describes it as China-nexus. The firm has not publicly tied the hackers to a specific Chinese government agency.

Sygnia has not disclosed the affected organizations or countries, and no U.S. victim has been publicly identified.

Cisco on Sept. 2 separately issued a critical security-hardening update for IOS XR, the router operating system involved in Sygnia’s investigation. Cisco said the update addresses seven groups of vulnerabilities discovered through internal testing and not known to be actively exploited.

Cisco’s advisory does not mention Fire Ant or Sygnia’s investigation, and Sygnia did not identify a Cisco vulnerability used in the attacks.

Hackers Hid Activity on Routers

Sygnia began investigating after researchers found a hidden network tunnel operating through a Cisco router but absent from the device’s normal configuration records. Investigators later found malware designed specifically for IOS XR.

Routers direct data between networks. Controlling one can allow an intruder to watch traffic passing through it or use the device as a path toward other systems.

Sygnia said Fire Ant hid activity by suppressing some router logs and changing the information administrators received when they checked the equipment, leaving them with an incomplete picture of what was running on the device.

Fire Ant also recorded network traffic from several Cisco routers and sent the files to outside servers, Sygnia said. Some of that collection was carried out through a legitimate administrator account.

Investigators traced one hidden connection to another compromised computer. From there, Sygnia said, Fire Ant tested connections to other high-value systems, including systems associated with critical infrastructure.

Sygnia documented scanning and connection attempts, but did not report that those downstream systems were successfully breached.

The firm described the approach as going after a “target behind the target”—first taking control of trusted network equipment and then looking for paths into other organizations.

Administrator Logins Targeted

Fire Ant also compromised systems that verify whether network administrators are authorized to log in to routers and other equipment. Those login verification systems use a protocol known as TACACS.

Sygnia found malware embedded in that login verification process that could capture administrator credentials as administrators signed in.

The firm named the tool TacTap and said it was unaware of that particular technique having been publicly documented before.

Sygnia said Fire Ant’s methods strongly overlap with those of UNC3886, another China-linked cyberespionage group previously investigated by Google-owned Mandiant. The firm stopped short of identifying the two as the same actor.

Similar techniques have been documented in other Chinese state-sponsored hacking campaigns, according to the United States and allied governments. Those campaigns were separate from Fire Ant.

A 2025 joint advisory from U.S. and allied cyber agencies described Chinese state-sponsored hackers targeting major telecommunications routers and other devices at the edges of networks.

The advisory described hidden tunnels, traffic collection, efforts to obtain administrator credentials, and use of compromised routers to reach additional networks. The agencies said much of the traffic collection they observed involved Cisco IOS devices.

The advisory did not identify Fire Ant.

Cisco’s Long Record in China

Separate from the Fire Ant investigation, Cisco has a decades-long record in China involving networking equipment, technical cooperation, and a large training program.

The U.S.–China Economic and Security Review Commission wrote in 2008 that Cisco routers and switches had become “cornerstones” of Golden Shield, a Ministry of Public Security project used for police networking, internet monitoring, censorship, and surveillance.

An internal Cisco presentation from 2002 described Golden Shield as a business opportunity and listed planning, construction, technical training, and operations maintenance among areas in which Cisco could participate.

The presentation cited Chinese authorities’ goal of using the system against Falun Gong and other groups they viewed as threats to Communist Party rule.

Cisco also developed a broad networking training program in China.

The company opened its first Networking Academy in mainland China at Fudan University in September 1998 and later expanded the program to universities across the country.

Cisco sued Huawei in 2003, alleging that the Chinese telecommunications company copied portions of Cisco’s networking software, technical documentation, and other intellectual property.

By April 2004, Cisco said it had 198 academies in China, with 17,370 students enrolled and 20,520 graduates.

That year, Cisco signed a $37.7 million agreement with China’s Ministry of Education covering networking courses, professional certifications, and instructor training at 35 national software colleges.

In October 2004, Cisco and Beijing University of Posts and Telecommunications established a network-security training center that Cisco said would train high level telecommunications security personnel and provide practical instruction to undergraduate, graduate, and doctoral students.

By 2009, Cisco said more than 100,000 students in China had received training through more than 250 networking academies.

California-based cybersecurity firm SentinelOne reported in 2025 that two people associated with companies named in the Salt Typhoon advisory appeared in Chinese university records as participants in a 2012 Cisco Networking Academy competition.

SentinelOne said corporate, patent, education, and employment records made it highly likely that the competitors were the same people later associated with the companies named in the Salt Typhoon advisory.

Those records do not connect either person to Fire Ant or establish that Cisco training was connected to their later cyber activity.

Initial Access Remains Unknown

Sygnia has not disclosed how Fire Ant first obtained the privileged access needed to compromise the Cisco routers.

Its report does not identify a Cisco vulnerability used in the attack. The Cybersecurity and Infrastructure Security Agency declined to comment on Sygnia’s report.

Sygnia, Cisco, and Google’s Mandiant did not respond to requests for comment by publication time.

Read Entire Article