“This behavior shifts the router’s role from a transit device to a collection platform,” Sygnia explains.
How Sygnia found an unexplained GRE tunnel on a Cisco IOS XR router
Incident responders at Sygnia traced the operation after discovering an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be justified by the device’s running configuration or commit history. That unexplained tunnel was the first visible sign that a network device normally used for transit had been altered to serve as a covert observation point.
From hypervisors to routers, TACACS servers, and Linux hosts
Sygnia reports that the threat actor, which the company calls Fire Ant, shifted its targeting away from VMware hypervisors and toward network infrastructure and management systems: Cisco routers, TACACS authentication servers, and Linux management hosts. On compromised routers, the researchers found custom malware that enabled persistence, covert connectivity, and traffic collection — behavior that extends the attacker’s reach beyond a single host and into network topology and administrative channels.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechniques observed: stealthy persistence, packet captures, and staging
- Persistence was achieved through a fake system service that ran the implant only during alternating hours, concealing its presence from routine checks.
- The malware selectively suppressed syslog messages to hide tunnel-related activity from legitimate administrators and established outbound Telnet connections to Fire Ant infrastructure.
- Attackers used administrative access to capture traffic from multiple routers and upload resulting PCAP files to external FTP servers — exposes internal topology, administrative connections, authentication flows, routing relationships, and traffic with connected networks.
- A concealed GRE tunnel connected a compromised router to a legacy Linux server that Fire Ant used as a staging and reconnaissance system. From that staging host, Sygnia observed probes into connected high-value environments over ports commonly used for SSH, web services, SMB/RPC, and RDP.
BridgeAgent backdoor disguised as a Zabbix monitoring agent
Sygnia discovered a previously undocumented backdoor the researchers named “BridgeAgent.” The actor disguised BridgeAgent as a legitimate Zabbix monitoring agent. On compromised Linux hosts it persisted as a root-level systemd service and supported TLS reverse shells and the execution of further payloads — providing an additional covert control channel beyond the modified routers.
Overlap with UNC3886 and evidence tampering
Sygnia says Fire Ant activity strongly overlaps with UNC3886, a Chinese espionage group previously documented by Google, but notes differences in filenames, paths, and implementation details. The company also warns that Fire Ant systematically tampers with system logs and records — including changing file timestamps — to obscure evidence useful to investigators. Sygnia advises that logs retrieved from compromised infrastructure should be validated against other data sources.
What this means for technologists and security teams, policymakers and regulators, and affected enterprises
- Technologists and security teams: Expect attackers to convert trusted network devices into long‑lived observation platforms. Teams should hunt for unexplained GRE interfaces, suppressed syslog entries, unusual outbound Telnet connections, and unauthorized PCAP uploads; Sygnia published IoCs, hunting and YARA rules to support that work.
- Policymakers and regulators: The campaign illustrates how compromises of upstream infrastructure and management hosts can create covert bridges into critical environments. Regulators assessing supply and network resilience may want to factor device-level abuse and log-tampering techniques into oversight and incident reporting frameworks.
- Affected enterprises and procurement leaders: Devices that traditionally function as transit elements — routers and authentication servers — can be repurposed for espionage. Procurement and operations teams should require visibility into device configurations, commit history integrity, and monitoring that can detect suppressed logs or unexplained encapsulation tunnels.
Sygnia’s report includes an extensive list of indicators of compromise (IoCs), along with hunting and YARA rules to detect Fire Ant activity. The company also highlights a broader defensive lesson: overall prevention metrics can mask what happens after initial access. The Blue Report 2026, cited in the source material, notes that “overall prevention scores can hide what happens after initial access,” and that its measurements — taken across 338 million simulations — show prevention drops sharply once attackers are using valid credentials.
Fire Ant’s combination of router‑level implants, a disguised backdoor on Linux hosts, selective log suppression, and covert traffic collection demonstrates a deliberate effort to turn trusted infrastructure into reconnaissance and pivoting platforms. Sygnia’s technical artifacts and YARA rules give defenders concrete detection steps; equally important is the reminder that investigators must validate logs against multiple sources because timestamps and records may have been altered.




