A China-linked threat actor known as Fire Ant has compromised Cisco IOS XR routers and other trusted infrastructure to spy on networks, steal credentials, maintain hidden access, and explore routes toward critical infrastructure.
The campaign shows how attackers can use routers not only to move traffic, but also as surveillance and attack platforms. Investigators discovered an unexplained GRE tunnel interface on a Cisco IOS XR router.
The interface was active, but there was no matching configuration or commit history to explain how it had been created. This suggested that the router’s operational state had been altered while normal administrative records were manipulated or hidden.
Fire Ant deployed several malicious components designed specifically for the IOS XR environment. One implant was placed in a startup path and disguised as a legitimate service.
It launched another component during selected hours, allowing the malware to remain persistent while reducing the chance of being noticed during routine checks.
Cisco Routers Turned Spy
The malware also modified the router’s logging process. It selectively prevented messages from being forwarded, which suppressed important security events.
Another component manipulated command execution and added filters to router output. This could hide tunnel settings, routing details, or other configuration information from administrators.

The attackers also used routers to capture network traffic. They generated PCAP files from several router interfaces and uploaded them to external FTP servers.
These packet captures could reveal internal network layouts, authentication activity, management connections, and traffic between connected environments.
By controlling routers, Fire Ant gained both reach and visibility. The devices provided a trusted position from which the attackers could observe network activity and plan movement into other systems.
The GRE tunnel connected the compromised environment to a legacy Linux system. Fire Ant used this host to conduct repeated connection attempts and scan systems associated with high-value and critical infrastructure environments.

The scans targeted common services, including SSH, HTTP, HTTPS, SMB, RPC, and RDP. Researchers found a backdoor named zabbixagent, designed to resemble a legitimate monitoring component.
The implant ran as root through a systemd service, stored encrypted configuration data, contacted external infrastructure over HTTPS, and supported reverse-shell access. It also launched additional tools on the Linux host, sygnia said.
Indicators of Compromise (IOCs)
| Filename | SHA1 | Role / Description |
|---|---|---|
bin/atd | C164BFC953C66E58B11FC280E69FD43B8F255839 | Custom SSH backdoor |
bin/gdm | — | Medusa-rootkit-related component |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN