China-Linked Hackers Hid In Cisco Routers, Stole Administrator Credentials: Report

ZeroHedge
Published
China-Linked Hackers Hid In Cisco Routers, Stole Administrator Credentials: Report

The short version

  • The Cisco logo is displayed in front of Cisco headquarters in San Jose, Calif., on Feb. 9, 2024.
  • Justin Sullivan/Getty Images The group also recorded traffic moving through the devices and used them to probe other high-value networks, according to the report.
  • The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment…
  • Sygnia tracks the group as Fire Ant and describes it as China-nexus.
  • The firm has not publicly tied the hackers to a specific Chinese government agency, nor have they disclosed the affected organizations or countries…

The story

China-Linked Hackers Hid In Cisco Routers, Stole Administrator Credentials: Report

Authored by Arthur Zhang via The Epoch Times,

A China-linked cyberespionage group compromised Cisco routers and hid its activity from the network administrators who managed them, cybersecurity firm Sygnia said in an Aug. 27 report.

The Cisco logo is displayed in front of Cisco headquarters in San Jose, Calif., on Feb. 9, 2024. Justin Sullivan/Getty Images

The group also recorded traffic moving through the devices and used them to probe other high-value networks, according to the report.

The hackers compromised systems that verify whether network administrators are authorized to log in to routers and other equipment, allowing them to capture administrator credentials, Sygnia said.

Sygnia tracks the group as Fire Ant and describes it as China-nexus. The firm has not publicly tied the hackers to a specific Chinese government agency, nor have they disclosed the affected organizations or countries, and no U.S. victim has been publicly identified.

Cisco on Sept. 2 separately issued a critical security-hardening update for IOS XR, the router operating system involved in Sygnia's investigation. Cisco said the update addresses seven groups of vulnerabilities discovered through internal testing and not known to be actively exploited.

Cisco's advisory does not mention Fire Ant or Sygnia's investigation, and Sygnia did not identify a Cisco vulnerability used in the attacks.

Hackers Hid Activity on Routers

Sygnia began investigating after researchers found a hidden network tunnel operating through a Cisco router but absent from the device's normal configuration records. Investigators later found malware designed specifically for IOS XR.

Routers direct data between networks. Controlling one can allow an intruder to watch traffic passing through it or use the device as a path toward other systems.

Sygnia said Fire Ant hid activity by suppressing some router logs and changing the information administrators received when they checked the equipment, leaving them with an incomplete picture of what was running on the device.

Fire Ant also recorded network traffic from several Cisco routers and sent the files to outside servers, Sygnia said. Some of that collection was carried out through a legitimate administrator account.

Investigators traced one hidden connection to another compromised computer. From there, Sygnia said, Fire Ant tested connections to other high-value systems, including systems associated with critical infrastructure.

Sygnia documented scanning and connection attempts, but did not report that those downstream systems were successfully breached.

The firm described the approach as going after a "target behind the target"-first taking control of trusted network equipment and then looking for paths into other organizations.

Administrator Logins Targeted

Fire Ant also compromised systems that verify whether network administrators are authorized to log in to routers and other equipment. Those login verification systems use a protocol known as TACACS.

Sygnia found malware embedded in that login verification process that could capture administrator credentials as administrators signed in.

The firm named the tool TacTap and said it was unaware of that particular technique having been publicly documented before.

Sygnia said Fire Ant's methods strongly overlap with those of UNC3886, another China-linked cyberespionage group previously investigated by Google-owned Mandiant. The firm stopped short of identifying the two as the same actor.

Similar techniques have been documented in other Chinese state-sponsored hacking campaigns, according to the United States and allied governments. Those campaigns were separate from Fire Ant.

A 2025 joint advisory from U.S. and allied cyber agencies described Chinese state-sponsored hackers targeting major telecommunications routers and other devices at the edges of networks.

The advisory described hidden tunnels, traffic collection, efforts to obtain administrator credentials, and use of compromised routers to reach additional networks. The agencies said much of the traffic collection they observed involved Cisco IOS devices.

The advisory did not identify Fire Ant.

Cisco's Long Record in China

Separate from the Fire Ant investigation, Cisco has a decades-long record in China involving networking equipment, technical cooperation, and a large training program.

The U.S.-China Economic and Security Review Commission wrote in 2008 that Cisco routers and switches had become "cornerstones" of Golden Shield, a Ministry of Public Security project used for police networking, internet monitoring, censorship, and surveillance.

An internal Cisco presentation from 2002 described Golden Shield as a business opportunity and listed planning, construction, technical training, and operations maintenance among areas in which Cisco could participate.

The presentation cited Chinese authorities' goal of using the system against Falun Gong and other groups they viewed as threats to Communist Party rule.

Cisco also developed a broad networking training program in China.

The company opened its first Networking Academy in mainland China at Fudan University in September 1998 and later expanded the program to universities across the country.

Cisco sued Huawei in 2003, alleging that the Chinese telecommunications company copied portions of Cisco's networking software, technical documentation, and other intellectual property.

By April 2004, Cisco said it had 198 academies in China, with 17,370 students enrolled and 20,520 graduates.

That year, Cisco signed a $37.7 million agreement with China's Ministry of Education covering networking courses, professional certifications, and instructor training at 35 national software colleges.

In October 2004, Cisco and Beijing University of Posts and Telecommunications established a network-security training center that Cisco said would train high level telecommunications security personnel and provide practical instruction to undergraduate, graduate, and doctoral students.

By 2009, Cisco said more than 100,000 students in China had received training through more than 250 networking academies.

California-based cybersecurity firm SentinelOne reported in 2025 that two people associated with companies named in the Salt Typhoon advisory appeared in Chinese university records as participants in a 2012 Cisco Networking Academy competition.

SentinelOne said corporate, patent, education, and employment records made it highly likely that the competitors were the same people later associated with the companies named in the Salt Typhoon advisory.

Those records do not connect either person to Fire Ant or establish that Cisco training was connected to their later cyber activity.

Initial Access Remains Unknown

Sygnia has not disclosed how Fire Ant first obtained the privileged access needed to compromise the Cisco routers.

Its report does not identify a Cisco vulnerability used in the attack. The Cybersecurity and Infrastructure Security Agency declined to comment on Sygnia's report.

Sygnia, Cisco, and Google's Mandiant did not respond to requests for comment by publication time.

Tyler Durden Thu, 09/03/2026 - 20:55
Read the full story at ZeroHedgeOriginal

Related Markets

All Markets
View full chart →
View Full Chart
View full chart →
View Full Chart
View full chart →
View Full Chart

Market data may be delayed. Not financial advice.

Powered by Gab AI

The Story At A Glance

Open the full breakdown on gab.ai

  • • China-linked hackers known as Fire Ant compromised Cisco routers to steal administrator credentials and monitor network traffic.

  • • The attackers used a tool called TacTap to intercept login processes and hid their presence by suppressing system logs.

  • • The breach allowed intruders to probe high-value targets, including critical infrastructure.
Context
Cisco has a long history of technical cooperation and training programs within China. This includes providing foundational networking equipment for the Chinese government's Golden Shield surveillance system.

Christian Perspective
This digital intrusion represents a manifestation of the deceit and lawlessness inherent in godless, communist regimes. It highlights the spiritual reality of a fallen world where hostile forces seek to undermine the security and sovereignty of others. We must recognize these technological attacks as part of a broader struggle against those who reject Christian order.

Implications
The vulnerability of critical infrastructure poses a direct threat to the stability and safety of the American nation. Protecting the digital borders of our country is essential to safeguarding the families and communities that form our social fabric. Compromised networks can lead to the subversion of the very systems that maintain national order.

Broader Trends
This incident reflects the ongoing struggle between the West and the rising influence of hostile foreign powers. It underscores the danger of globalist economic entanglements that allow adversarial nations to embed themselves within our vital technological infrastructure. The pattern of China leveraging Western technology for its own state control is a clear and present danger.

Takeaway
America First policies must prioritize the total decoupling of critical infrastructure from Chinese-linked technology. We must demand absolute digital sovereignty to protect our people from foreign subversion. Strengthening our national defenses requires a vigilant, unyielding stance against those who seek to exploit our openness.

Want to join the conversation about this story?

Join our community at Gab.com

Alto is powered by

Gab AI

The one AI they can't control. Our exclusive AI model trained to uphold Christian values and traditional principles in every interaction.

More to read

Recent stories from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What does gas cost in California right now?Current statewide average
  2. How does California rank on taxes and cost of living?Taxes, wages, cost of living
  3. What were the latest California lottery numbers?Recent winning numbers
  4. Who represents California in Congress?House and Senate members
  5. What are California's voter ID rules?ID rules and deadlines
  6. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  7. Where does $75,000 rank in California?Census percentile — national and state
  8. What federal tax bracket is $80,000 (single)?Marginal and effective rate on the next page
  9. What's Alto covering on the Finance desk?Latest headlines on this beat
  10. What else is Alto tracking on Federal Reserve & Interest Rates?Topic hub with related coverage
  11. What else is Alto tracking on Inflation?Topic hub with related coverage

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Markets Freely

Trade ideas, earnings, and the Fed with investors who aren't waiting on a moderator's approval.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.