Sygnia’s latest Fire Ant report is a clean example of why “trusted infrastructure” cannot be treated as background plumbing during an intrusion. The China-nexus actor did not just pursue ordinary servers and workstations. Sygnia describes activity across Cisco IOS XR routers, TACACS authentication infrastructure, Linux management hosts, GRE tunnel paths, and router-level packet capture workflows.
For defenders, the lesson is direct: the systems that route traffic, authenticate administrators, manage segmentation, and preserve logs are also high-value targets. If those systems are compromised, an attacker can gain reach, visibility, persistence, and the ability to distort the evidence trail at the same time.
What Sygnia reported
Sygnia says Fire Ant remained active into 2026 and expanded from its previously reported hypervisor-focused tradecraft into the infrastructure layer that organizations rely on for connectivity and administration. The actor allegedly used compromised routers as operational platforms, manipulated logging and command output, collected traffic from multiple routers, and explored paths into connected high-value networks, including critical infrastructure environments.
The report also highlights compromise of TACACS infrastructure — a serious escalation point because TACACS sits in the administrative authentication path for routers and other network devices. If an attacker owns the system that validates administrator access and records activity, defenders may lose confidence in both credential integrity and the audit trail.
On the Linux side, Sygnia described management hosts and tunnel-connected systems being used as staging and reconnaissance nodes. One implant, tracked as BridgeAgent, reportedly masqueraded as monitoring infrastructure, persisted through systemd, loaded encrypted configuration from disk, and supported outbound command-and-control behavior over TLS.
Why this matters for SMBs and government contractors
Many small and mid-sized organizations do not have large security teams, but they still depend on the same categories of infrastructure: VPNs, routers, jump boxes, virtualization hosts, RMM platforms, authentication servers, SIEM collectors, and network monitoring tools. Government contractors may also maintain trusted paths into customer, partner, or cloud environments. That makes the management layer a force multiplier for a capable attacker.
The risk is not limited to “someone logged into a router.” The real issue is that a compromised infrastructure layer can become the attacker’s internal vantage point. From there, they can observe traffic, harvest administrative credentials, route around segmentation, hide tunnel state, suppress logs, and test reachability into environments that were supposed to be reachable only through trusted operations paths.
Defensive takeaways
- Treat routers and management appliances as monitored assets. Network devices need centralized logging, configuration backup, image integrity checks, AAA monitoring, and incident-response playbooks — not just uptime checks.
- Validate device state against more than running config. Compare running configuration, committed configuration, operational interfaces, routing tables, VRFs, tunnel state, process lists, and out-of-band telemetry. A hidden tunnel or modified command output can make a normal CLI review misleading.
- Harden TACACS, RADIUS, and identity chokepoints. Segment them, restrict admin access, rotate secrets, monitor authentication anomalies, and verify logs against independent sources. If authentication infrastructure is suspect, assume downstream device logs may also be suspect.
- Control egress from infrastructure networks. Routers, jump hosts, monitoring servers, and management VMs should not freely reach arbitrary FTP, SSH, HTTPS, or Telnet destinations. Alert on unusual outbound transfers, PCAP exports, and unexpected tunnels.
- Build a trusted-infrastructure hunt list. Include hypervisors, network controllers, backup servers, SIEM/log collectors, jump boxes, RMM tools, VPN concentrators, TACACS/RADIUS servers, and monitoring platforms. These are attacker leverage points.
- Preserve evidence from multiple layers. When infrastructure compromise is possible, collect device configs, memory/process artifacts where feasible, NetFlow, firewall logs, packet captures, authentication logs, EDR data from management hosts, and cloud/control-plane audit records.
Bulwark Black assessment
Fire Ant’s reported activity reinforces a pattern we keep seeing across modern intrusions: attackers are moving toward infrastructure that gives them authority over the environment itself. Edge devices, hypervisors, authentication servers, and management hosts are attractive because they sit above ordinary endpoint visibility and below business workflows. They are trusted by default and often under-instrumented.
The proper defensive posture is to stop treating the management plane as invisible. If a device can route traffic, authenticate administrators, broker remote access, collect telemetry, or manage other systems, it should be in scope for hardening, detection, backup, and incident response. For government contractors especially, trusted infrastructure compromise is not just an internal IT problem — it can become a partner, customer, and mission-risk problem.
Original source: Sygnia — Fire Ant Evolves: From Hypervisors to Trusted Infrastructure

