▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

Sygnia Reveals New Activity by China-Nexus Threat Actor Fire Ant Targeting Trusted Infrastructure

Sygnia, the foremost global cyber readiness and response team, released the findings of their investigation into ongoing activity by a China-nexus threat actor, targeting key infrastructure that route...

Immagine

Incident Response leader reveals long-running espionage activity abusing routers, authentication systems and Linux management hosts to collect intelligence and explore paths toward connected high-value environments.

SINGAPORE & TEL-AVIV, Israel & NEW YORK: Sygnia, the foremost global cyber readiness and response team, released the findings of their investigation into ongoing activity by a China-nexus threat actor, targeting key infrastructure that routes, authenticates, connects, and manages high-value environments. Tracked by Sygnia as ‘Fire Ant’, the adversary leveraged novel attack tools and methods to target Cisco IOS XR routers and turn them into operational platforms that suppress evidence of threat actor activity, collect traffic and credentials, and enable Fire Ant to explore other access points with the goal of spreading to other organizations.

The 2026 findings represent an evolution of Fire Ant’s activity, expanding their focus beyond their 2025 activity of deep persistence within virtualization infrastructure targeting VMware ESXi and vCenter environments to strategic infrastructure abuse.

“Fire Ant didn’t just compromise systems. It compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure many organizations overlook as legacy technology became the attacker’s vantage point for reach, visibility, and control,” said Asaf Perlman, Director of Incident Response at Sygnia. “That is what makes this research so important: the significance extended beyond the initially compromised environment, as the affected infrastructure could provide a path toward other connected high-value environments.”

Key findings of the threat report include:

  • ‘Target behind the target’ – 2026 activity compromised both direct and connected high-value environments, targeting infrastructure that other systems depend on to communicate and be administered. Router infrastructure was exploited for covert connectivity and traffic collection to expand the threat actor’s reach to connected high-value environments.
  • Authentication chokepoints – The threat actor compromised TACACS infrastructure to intercept administrative authentication flows, collect credentials, and weaken confidence in administrative audit trails.
  • New attack tools – Sygnia’s investigation uncovered two novel tools. A masquerading implant tracked by Sygnia as BridgeAgent that is configured for tunnelling and persistence through a zabbix_agent.service systemd unit, set to run as root with automatic restart behavior and a TACACS credential-collection toolset tracked as TacTap that enabled library injection, accepted-session interception, and Unix-socket file-descriptor handoff.
  • Resilient persistence – Fire Ant established a resilient access layer through long-lived implants across Linux management infrastructure, including Medusa-related components, custom SSH backdoors, Zabbix-masquerading malware, and packet-triggered backdoors.
  • Defense evasion and evidence manipulation – The actor also manipulated the evidence layer by hiding logs, hiding commit activity, suppressing AAA requests, suppressing SNMP traps and filtering command output. On Linux systems, the actor deleted files after execution, left processes running from deleted paths, disabled SELinux, tampered with logs and modified firewall rules.

The new intelligence value from Sygnia's investigation highlights a campaign targeting a highly interconnected environment where routers, TACACS servers and Linux management hosts were used as part of a broader access and collection layer. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim.

Learn more about Fire Ant’s 2026 activity in the latest threat research, “Fire Ant Evolves: From Hypervisors to Trusted Infrastructure.”

About Sygnia

Sygnia is the world’s foremost incident response and cyber readiness team. It applies creative approaches and bold solutions to each phase of an organization’s security journey, meeting them where they are to ensure cyber resilience. Sygnia is the trusted advisor and service provider of leading organizations worldwide, including Fortune 100 companies. Sygnia is a Temasek company, part of the ISTARI Collective.

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

CrowdStrike and Google Announce the Falcon Platform on Google Cloud

Fal.Con 2026--CrowdStrike (NASDAQ: CRWD) today announced the CrowdStrike Falcon® platform is now available on Google Cloud infrastructure, giving customers…

Sygnia Reveals New Activity by China-Nexus Threat Actor Fire Ant Targeting…

Sygnia, the foremost global cyber readiness and response team, released the findings of their investigation into ongoing activity by a China-nexus threat…

Mitsubishi Electric Develops Task-Aware Unified Source Separation Technology

Mitsubishi Electric Corporation (TOKYO: 6503) announced today the development of its Task-Aware Unified Source Separation (TUSS) technology, which enables…

Mitsubishi Electric to Exhibit at CEATEC 2026

Mitsubishi Electric Corporation (TOKYO: 6503) announced today that it will exhibit advanced technologies and solutions as the Mitsubishi Electric Group…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!