Skip to content
Sygnia Reveals New Activity by China

Sygnia Reveals New Activity by China

Sg.Finance.Yahoo August 30, 2026

Incident Response leader reveals long-running espionage activity abusing routers, authentication systems and Linux management hosts to collect intelligence and explore paths toward connected high-value environments.

SINGAPORE & TEL-AVIV, Israel & NEW YORK, August 30, 2026 --( BUSINESS WIRE )--Sygnia, the foremost global cyber readiness and response team, released the findings of their investigation into ongoing activity by a China-nexus threat actor, targeting key infrastructure that routes, authenticates, connects, and manages high-value environments. Tracked by Sygnia as 'Fire Ant', the adversary leveraged novel attack tools and methods to target Cisco IOS XR routers and turn them into operational platforms that suppress evidence of threat actor activity, collect traffic and credentials, and enable Fire Ant to explore other access points with the goal of spreading to other organizations.

The 2026 findings represent an evolution of Fire Ant's activity, expanding their focus beyond their 2025 activity of deep persistence within virtualization infrastructure targeting VMware ESXi and vCenter environments to strategic infrastructure abuse.

"Fire Ant didn't just compromise systems. It compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure many organizations overlook as legacy technology became the attacker's vantage point for reach, visibility, and control," said Asaf Perlman, Director of Incident Response at Sygnia. "That is what makes this research so important: the significance extended beyond the initially compromised environment, as the affected infrastructure could provide a path toward other connected high-value environments."

Key findings of the threat report include:

'Target behind the target' – 2026 activity compromised both direct and connected high-value environments, targeting infrastructure that other systems depend on to communicate and be administered. Router infrastructure was exploited for covert connectivity and traffic collection to expand the threat actor's reach to connected high-value environments.

Authentication chokepoints – The threat actor compromised TACACS infrastructure to intercept administrative authentication flows, collect credentials, and weaken confidence in administrative audit trails.

New attack tools – Sygnia's investigation uncovered two novel tools. A masquerading implant tracked by Sygnia as BridgeAgent that is configured for tunnelling and persistence through a zabbix_agent.service systemd unit, set to run as root with automatic restart behavior and a TACACS credential-collection toolset tracked as TacTap that enabled library injection, accepted-session interception, and Unix-socket file-descriptor handoff.

Resilient persistence – Fire Ant established a resilient access layer through long-lived implants across Linux management infrastructure, including Medusa-related components, custom SSH backdoors, Zabbix-masquerading malware, and packet-triggered backdoors.

Defense evasion and evidence manipulation – The actor also manipulated the evidence layer by hiding logs, hiding commit activity, suppressing AAA requests, suppressing SNMP traps and filtering command output. On Linux systems, the actor deleted files after execution, left processes running from deleted paths, disabled SELinux, tampered with logs and modified firewall rules.