Fire Ant Moves Into Cisco Router Control Planes

Sygnia said Fire Ant has expanded its campaign from VMware into Cisco IOS XR routers, TACACS servers, and Linux management hosts, turning those systems into collection points for traffic, credentials, and log data. The firm said the actor then used that foothold to look toward connected high-value environments, including critical infrastructure. The compromise matters because control-plane access is not just another host breach. Once the actor can sit on routers or centralized authentication systems, it can watch trusted traffic pass by, harvest administrator credentials, and suppress the telemetry defenders would normally use to reconstruct the intrusion. For telecom and critical-infrastructure networks that rely on IOS XR and centralized admin authentication, the exposure sits in the management layer itself: a single foothold there can give an operator the network’s own vantage point, while also making later reconstruction much harder.

Part of the PlainSec briefing for 2026-08-31

Every edition of this story: Fire Ant Moves Into Cisco Router Control Planes

Sources