# Fire Ant campaign targets Cisco routers and TACACS servers

_Monday, August 31, 2026 at 5:04 AM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Fire Ant campaign targets Cisco routers and TACACS servers — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxYI5Ntk3CPoEGUHNQbd80hij-0QLnz3V_HBU3aXV-mvQq98IE6xsRlbuwZ2PNbbSV7dA-HlNfqRWj0_bd3XpQCOPt9R2gS3PJMm8lfMP_9IoKyhDNbY9NOotNDHO68v2DSUT_R-0UYTqZQc16DJM7OqS8_35iVUMqyy3GrUt7iMaIWz6iW6OSP2ddiDc/s1700-nu-rw-lo-l85-e365/cisco-creds.jpg)

Incident-response firm Sygnia reported that the China-nexus actor it tracks as Fire Ant expanded a campaign to Cisco IOS XR routers, TACACS servers and Linux management hosts. Sygnia said compromised routers captured traffic, harvested credentials and suppressed logs and telemetry. The firm found a TACACS credential-collection toolset and router implants designed to hide tunnel configuration. It assessed strong overlap with UNC3886 reporting but did not make a conclusive attribution.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html)

---
Canonical: https://techandbusiness.org/newswire/s1HMWxDSViQ9t3bUuAIZ5D
Retrieved: 2026-08-31T13:40:56.513Z
Publisher: Tech & Business (techandbusiness.org)
