China-Linked Hackers Hid In Cisco Routers, Stole Administrator Credentials: Report
.jpg?itok=7pLVxuRc)
The short version
- The Cisco logo is displayed in front of Cisco headquarters in San Jose, Calif., on Feb. 9, 2024.
- Justin Sullivan/Getty Images The group also recorded traffic moving through the devices and used them to probe other high-value networks, according to the report.
- The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment…
- Sygnia tracks the group as Fire Ant and describes it as China-nexus.
- The firm has not publicly tied the hackers to a specific Chinese government agency, nor have they disclosed the affected organizations or countries…
The story
Authored by Arthur Zhang via The Epoch Times,
A China-linked cyberespionage group compromised Cisco routers and hid its activity from the network administrators who managed them, cybersecurity firm Sygnia said in an Aug. 27 report.
The group also recorded traffic moving through the devices and used them to probe other high-value networks, according to the report.
The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment, allowing them to capture administrator credentials, Sygnia said.
Sygnia tracks the group as Fire Ant and describes it as China-nexus. The firm has not publicly tied the hackers to a specific Chinese government agency, nor have they disclosed the affected organizations or countries, and no U.S. victim has been publicly identified.
Cisco on Sept. 2 separately issued a critical security-hardening update for IOS XR, the router operating system involved in Sygnia's investigation. Cisco said the update addresses seven groups of vulnerabilities discovered through internal testing and not known to be actively exploited.
Cisco's advisory does not mention Fire Ant or Sygnia's investigation, and Sygnia did not identify a Cisco vulnerability used in the attacks.
Hackers Hid Activity on Routers
Sygnia began investigating after researchers found a hidden network tunnel operating through a Cisco router but absent from the device's normal configuration records. Investigators later found malware designed specifically for IOS XR.
Routers direct data between networks. Controlling one can allow an intruder to watch traffic passing through it or use the device as a path toward other systems.
Sygnia said Fire Ant hid activity by suppressing some router logs and changing the information administrators received when they checked the equipment, leaving them with an incomplete picture of what was running on the device.
Fire Ant also recorded network traffic from several Cisco routers and sent the files to outside servers, Sygnia said. Some of that collection was carried out through a legitimate administrator account.
Investigators traced one hidden connection to another compromised computer. From there, Sygnia said, Fire Ant tested connections to other high-value systems, including systems associated with critical infrastructure.
Sygnia documented scanning and connection attempts, but did not report that those downstream systems were successfully breached.
The firm described the approach as going after a "target behind the target"-first taking control of trusted network equipment and then looking for paths into other organizations.
Administrator Logins Targeted
Fire Ant also compromised systems that verify whether network administrators are authorized to log in to routers and other equipment. Those login verification systems use a protocol known as TACACS.
Sygnia found malware embedded in that login verification process that could capture administrator credentials as administrators signed in.
The firm named the tool TacTap and said it was unaware of that particular technique having been publicly documented before.
Sygnia said Fire Ant's methods strongly overlap with those of UNC3886, another China-linked cyberespionage group previously investigated by Google-owned Mandiant. The firm stopped short of identifying the two as the same actor.
Similar techniques have been documented in other Chinese state-sponsored hacking campaigns, according to the United States and allied governments. Those campaigns were separate from Fire Ant.
A 2025 joint advisory from U.S. and allied cyber agencies described Chinese state-sponsored hackers targeting major telecommunications routers and other devices at the edges of networks.
The advisory described hidden tunnels, traffic collection, efforts to obtain administrator credentials, and use of compromised routers to reach additional networks. The agencies said much of the traffic collection they observed involved Cisco IOS devices.
The advisory did not identify Fire Ant.
Cisco's Long Record in China
Separate from the Fire Ant investigation, Cisco has a decades-long record in China involving networking equipment, technical cooperation, and a large training program.
The U.S.-China Economic and Security Review Commission wrote in 2008 that Cisco routers and switches had become "cornerstones" of Golden Shield, a Ministry of Public Security project used for police networking, internet monitoring, censorship, and surveillance.
An internal Cisco presentation from 2002 described Golden Shield as a business opportunity and listed planning, construction, technical training, and operations maintenance among areas in which Cisco could participate.
The presentation cited Chinese authorities' goal of using the system against Falun Gong and other groups they viewed as threats to Communist Party rule.
Cisco also developed a broad networking training program in China.
The company opened its first Networking Academy in mainland China at Fudan University in September 1998 and later expanded the program to universities across the country.
Cisco sued Huawei in 2003, alleging that the Chinese telecommunications company copied portions of Cisco's networking software, technical documentation, and other intellectual property.
By April 2004, Cisco said it had 198 academies in China, with 17,370 students enrolled and 20,520 graduates.
That year, Cisco signed a $37.7 million agreement with China's Ministry of Education covering networking courses, professional certifications, and instructor training at 35 national software colleges.
In October 2004, Cisco and Beijing University of Posts and Telecommunications established a network-security training center that Cisco said would train high level telecommunications security personnel and provide practical instruction to undergraduate, graduate, and doctoral students.
By 2009, Cisco said more than 100,000 students in China had received training through more than 250 networking academies.
California-based cybersecurity firm SentinelOne reported in 2025 that two people associated with companies named in the Salt Typhoon advisory appeared in Chinese university records as participants in a 2012 Cisco Networking Academy competition.
SentinelOne said corporate, patent, education, and employment records made it highly likely that the competitors were the same people later associated with the companies named in the Salt Typhoon advisory.
Those records do not connect either person to Fire Ant or establish that Cisco training was connected to their later cyber activity.
Initial Access Remains Unknown
Sygnia has not disclosed how Fire Ant first obtained the privileged access needed to compromise the Cisco routers.
Its report does not identify a Cisco vulnerability used in the attack. The Cybersecurity and Infrastructure Security Agency declined to comment on Sygnia's report.
Sygnia, Cisco, and Google's Mandiant did not respond to requests for comment by publication time.
Related Markets
All MarketsMarket data may be delayed. Not financial advice.
Powered by Gab AI
The Story At A Glance
Open the full breakdown on gab.ai
- • China-linked hackers known as Fire Ant compromised Cisco routers to steal administrator credentials and monitor network traffic.
- • The attackers used a tool called TacTap to intercept login processes and hid their presence by suppressing system logs.
- • The breach allowed intruders to probe high-value targets, including critical infrastructure.
Cisco has a long history of technical cooperation and training programs within China. This includes providing foundational networking equipment for the Chinese government's Golden Shield surveillance system.
Christian Perspective
This digital intrusion represents a manifestation of the deceit and lawlessness inherent in godless, communist regimes. It highlights the spiritual reality of a fallen world where hostile forces seek to undermine the security and sovereignty of others. We must recognize these technological attacks as part of a broader struggle against those who reject Christian order.
Implications
The vulnerability of critical infrastructure poses a direct threat to the stability and safety of the American nation. Protecting the digital borders of our country is essential to safeguarding the families and communities that form our social fabric. Compromised networks can lead to the subversion of the very systems that maintain national order.
Broader Trends
This incident reflects the ongoing struggle between the West and the rising influence of hostile foreign powers. It underscores the danger of globalist economic entanglements that allow adversarial nations to embed themselves within our vital technological infrastructure. The pattern of China leveraging Western technology for its own state control is a clear and present danger.
Takeaway
America First policies must prioritize the total decoupling of critical infrastructure from Chinese-linked technology. We must demand absolute digital sovereignty to protect our people from foreign subversion. Strengthening our national defenses requires a vigilant, unyielding stance against those who seek to exploit our openness.
Want to join the conversation about this story?
Join our community at Gab.com→
Gab AI
The one AI they can't control. Our exclusive AI model trained to uphold Christian values and traditional principles in every interaction.