The Attack Moves to the Routers Between Networks
Sygnia reports a China-linked group turning Cisco IOS XR routers and TACACS servers into a collection platform — compromising the layer that authenticates and audits administrators.

Sygnia has published new findings on the operation it tracks as Fire Ant, a China-linked group that overlaps with the cluster Mandiant calls UNC3886, implicated in attacks on strategic organisations between 2022 and 2024 and still active in 2026. The latest campaign centres on Cisco IOS XR routers, with new tooling for persistence and for harvesting credentials.
The strategic shift is the story. The targeting has moved from endpoints, servers and cloud workloads to the infrastructure between environments: routers, hypervisors, access appliances and Linux management hosts. Attackers captured traffic from multiple Cisco routers simultaneously and uploaded it to external infrastructure — seeking vantage points across the environment rather than a single foothold. A compromised router is not a destination, it is a position from which to watch everything that passes.
Most consequential is the compromise of TACACS servers. TACACS is the administrative checkpoint that authenticates users, authorises commands and records what was done — the control that most network security models quietly depend on. Owning it allows credential harvesting in transit and, worse, blurs the line between legitimate and malicious administrative activity: when the system that decides what is authorised is itself controlled, the audit trail stops being evidence. Sygnia's incident response director Asaf Perlman described the group as compromising the trust layer rather than just systems. Evidence suppression followed the same logic — hiding logs, deleting files, tampering with firewall rules.
Sygnia says 2026 compromises affected both victims and third-party environments, exploiting infrastructure relationships to reach high-value networks and critical infrastructure. Affected organisations were not named.
For industrial operators the practical reading is uncomfortable, because this is exactly the equipment that sits at the boundary of an OT network and is usually managed by a corporate network team rather than by operations. It is also the equipment most often left in place through end of life, since replacing a working router has no operational benefit. The pattern is not new — Volt Typhoon targeted end-of-life Cisco routers in the US, UK and Australia in 2024, more than 1,000 Cisco network devices were targeted in the Salt Typhoon campaign, and federal warnings on Cisco appliances ran repeatedly through late 2025 — but the addition of the authentication layer raises the ceiling on what a compromise means.
The defensive implication is less about patching than about assumption. If the boundary devices and the authentication servers can be owned, then segmentation designs that treat administrative access as inherently trustworthy have a gap at exactly the point where they are hardest to monitor.
Source: The Record