Visualização de leitura
1-15 August 2026 Cyber Attacks Timeline Infographic
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks.
Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising hypervisors into routers, authentication servers, and Linux management hosts, the unglamorous plumbing that decides who gets to log in where and what gets recorded when they do.
The investigation started with something that looked like a minor configuration mistake. A tunnel interface showed up as active on a Cisco IOS XR router with no corresponding entry in the configuration history, no commit anyone could point to that explained how it got there.
“The investigation began with an anomaly that appeared, at first, to be a configuration inconsistency: a tunnel interface became operational on a Cisco IOS XR router even though no corresponding running configuration or commit history could explain its creation. The interface was associated with a specific VRF and used GRE encapsulation, but standard configuration review did not provide a reliable explanation for how it appeared.” reads the report. “This discrepancy became a key investigative lead because it suggested that the device’s operational state could no longer be trusted to match the configuration and audit records visible to administrators.”
That single inconsistency became the thread that unraveled the whole operation, because it meant the router’s own records could no longer be trusted to reflect what the device was actually doing.
What Fire Ant built inside that router wasn’t generic malware bolted onto Linux. The toolkit was purpose-written for IOS XR’s own internals, hooking into logging, command execution, and routing functions directly. One component disguised itself as a legitimate boot service and ran on a bizarre schedule, active only during odd-numbered hours and shut off during even ones, apparently timed to dodge routine inspection windows. Another modified the router’s own syslog function so that any log message not containing the word “Health” would silently vanish instead of being recorded, a filter so specific it reads like something built to survive a very particular kind of audit.
Following that anomalous tunnel led investigators to a second compromised machine, an aging Linux system acting as the tunnel’s far end. From there, Fire Ant wasn’t just maintaining access, it was actively scanning outward toward other high-value networks, probing SSH, RDP, and web ports on systems connected through the compromised infrastructure.
“The actor appeared to use the compromised environment as an infrastructure platform from which it could explore reachability into connected high-value networks, including critical infrastructure.” states Sygnia. “In this model, routers, TACACS servers and jump hosts are not peripheral assets. They are the path to the target behind the target.”

The authentication layer got its own dedicated attack, and this is the part that should concern anyone who thinks compromised credentials are the worst-case scenario. Fire Ant injected a malicious library directly into a running TACACS authentication daemon, the software responsible for approving administrator logins across network devices, then intercepted live sessions as they were accepted and quietly copied the credential material flowing through. That’s not stealing a password from a phishing page; that’s sitting inside the process whose entire job is deciding who to trust, watching every legitimate login happen in real time.
“The acpid component embedded a modified IOS XR syslog library. In the modified evsyslog flow, log delivery was routed through a custom wrapper that checked for the string “Health” before calling mq_send. When the condition was not met, the wrapper returned a success-like value without forwarding the message, indicating selective manipulation of router log delivery.” states the report.
Fire Ant also used deep, persistent backdoors on Linux systems. Some had remained dormant since 2025 and were disguised as normal system services, making them easy to overlook. One even posed as SentinelOne’s security agent and stayed active in memory after its file was deleted, making standard disk-based forensic checks ineffective on their own.
Perhaps the most technically distinctive piece was a backdoor that didn’t listen on any port at all in the conventional sense. Instead it silently inspected raw network traffic, waiting for specific packets carrying an embedded magic string before it would activate and open an interactive shell. This design shares real code-level overlap with tooling publicly tied to UNC3886, a China-nexus espionage cluster Google and Mandiant have tracked for years, though the specific activation strings and packet-handling logic here differ enough from earlier public reporting that Sygnia treats it as an evolution rather than a straight reuse.
“The key choice is notable because Mandiant previously documented UNC3886 TACACS credential-collection tooling in which captured credential records were also XORed with 0xEF before being written to a credential log file.” continues the report.
Once inside, Fire Ant didn’t just avoid detection, it actively edited the evidence. Login records in Linux’s own wtmp, utmp, and btmp files got rewritten to swap out the router’s real IP address for an internal one, and sudo-related entries were stripped from system logs to erase any trace of privilege escalation. Sygnia’s core warning for defenders cuts against a habit most incident responders have built their careers on: logs are not automatically ground truth anymore, and any investigation into infrastructure this deeply compromised has to cross-check log evidence against memory, disk state, and network telemetry independently rather than trusting any single source on its own.
The bigger concern is that Fire Ant was not mainly interested in the systems it first compromised. It used them as a stepping stone into more valuable networks connected through trusted routing and authentication relationships — what Sygnia calls the “target behind the target.” This means edge routers, TACACS servers and Linux jump hosts can be just as important to protect as systems holding sensitive data, especially when they connect to critical infrastructure. These often-overlooked systems can give a patient and well-resourced attacker a trusted path deeper into the environment, making them a valuable target rather than an unimportant middle layer.
“The central lesson is that defenders must protect more than the systems that store sensitive data. They must protect the infrastructure that makes other systems reachable, trusted, and observable.” concludes the report. “When that layer is compromised, the impact extends beyond a single organization: the actor may gain a vantage point for collection, a path toward connected targets, and the ability to make trusted infrastructure tell an incomplete story.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Fire Ant)
Google Tracks Russian Cyber Espionage Clusters
Google tracks suspected Russian cyber espionage clusters abusing logins. Learn how these Russian cyber espionage clusters target global officials.
Related Posts:
- OpenAI Disrupts Russian Influence Campaign Promoting Fake Think Tank
- NIST Asks for Help Putting People First in Cybersecurity
- GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
The post Google Tracks Russian Cyber Espionage Clusters appeared first on Daily CyberSecurity.
July 2026 Cyber Attacks Statistics
16-31 July 2026 Cyber Attacks Timeline Infographic
16-31 July 2026 Cyber Attacks Timeline
1-15 July 2026 Cyber Attacks Timeline Infographic
1-15 July 2026 Cyber Attacks Timeline
H1 2026 Cyber Attacks Statistics Infographic
EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions

The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.
According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted cyber sabotage against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader cyber operations against governments and critical infrastructure across Europe.
Russia Cyberattack Linked to FSB's Center 16 Operations
The European Union said Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.
The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.
British authorities described last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.
Poland Attack Nearly Triggered Major Blackout
The cyber incident targeting Poland's energy infrastructure last winter was initially linked by cybersecurity firms ESET and Dragos to Sandworm, a threat group associated with Russia's military intelligence agency.
However, Poland's national cybersecurity agency, CERT Polska, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.
Separately, Poland's domestic intelligence service warned in May that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.
EU and UK Expand Cyber Sanctions
In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.
The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer malware, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.
EU foreign policy chief Kaja Kallas said Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.
She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.
France Details FSB Activities
France also announced additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.
A technical report from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.
French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of data from a research institute working with the French defense industry in February 2025.
France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the 2024 Paris Olympic and Paralympic Games.
Allied Advisory Warns of Ongoing Threats
Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a joint cybersecurity advisory warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.
The United Kingdom separately sanctioned individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the malware have been used to support Russian espionage operations globally. According to the UK's National Crime Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.
British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.
The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has dismissed European allegations of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.