Report: Hacker Intrusions Related to Cisco Routers in China

On September 3, 2026, according to a report released by the cybersecurity company Sygnia on August 27, a network spy organization linked to China’s Communist Party infiltrated Cisco routers, concealing its activities. The organization also monitored network traffic transmitted through these devices to explore other high-value networks.

Sygnia stated that the hackers breached the system used to verify if network administrators had authorization to log into routers and other devices, intercepting administrator credentials.

The network spy organization, dubbed “Fire Ant” by Sygnia, was classified as affiliated with China’s Communist Party, although the affected organizations or countries have not been disclosed, and no American victims have been reported.

On September 2, Cisco released a critical security update for the IOS XR router operating system mentioned in Sygnia’s investigation. The update addressed seven vulnerabilities discovered through internal testing, with no known exploitation of these vulnerabilities thus far.

Cisco’s security advisory did not mention Fire Ant or Sygnia’s investigation, and Sygnia did not specify which Cisco vulnerabilities were exploited in the hacker attacks.

Sygnia’s investigation began when researchers discovered a covert network tunnel running through Cisco routers that was completely invisible in the devices’ normal configuration logs. Subsequently, researchers found malicious software specifically targeting IOS XR.

Fire Ant obscured its activities by suppressing portions of router logs and altering the information received when administrators viewed the devices, preventing administrators from fully understanding the content running on the devices.

Additionally, Fire Ant recorded network traffic from multiple Cisco routers and transmitted files to external servers, with some data collection done through legitimate administrator accounts.

Investigators traced one covert connection to another compromised computer. Starting from there, Fire Ant tested connections to other high-value systems, including critical infrastructure.

Although the scans and connection attempts were recorded, no successful breaches into downstream systems were reported.

Fire Ant also infiltrated the validation system used to check if network administrators had authorization to log into routers and other devices. This validation system employed a protocol known as TACACS.

During the validation process, Sygnia found embedded malicious software that captured credentials when administrators logged in.

Sygnia noted similarities between Fire Ant’s tactics and those of another network spy organization, UNC3886, associated with China’s Communist Party, previously investigated by Mandiant, a subsidiary of Google.

The United States and its allied governments have previously documented similar tactics in other hacker operations with Chinese state-backed backgrounds.

In a joint announcement by U.S. and allied cybersecurity agencies in 2025, attacks by state-backed Chinese hackers on large telecommunications routers and other network edge devices were described, including covert tunnels, traffic collection, acquiring administrator credentials, and using compromised routers to infiltrate other networks. Most of these activities involved Cisco IOS devices.

However, Fire Ant was not mentioned in the announcement.

Sygnia has not disclosed how Fire Ant initially obtained the necessary charter access permissions to infiltrate Cisco routers or specifically which Cisco vulnerabilities were exploited in the attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) declined to comment on Sygnia’s report.

At the time of publication, neither Sygnia, Cisco, nor Mandiant under Google had responded to requests for comments.