China-Linked Fire Ant Campaign Targets Cisco Routers for Espionage

China-Linked Fire Ant Campaign Targets Cisco Routers for Espionage

First seen 8 Sep 2026, 17:13 UTC EscudodigitalKrypt3Ia.Wordpress 80.7

Article Content

Browse articles
ThreatCluster

Chinese threat actors, identified as part of the Fire Ant operation, are intensifying attacks on Cisco IOS XR routers, compromising these devices to gather intelligence and credentials. The campaign has been linked to the UNC3886 group, which has a history of targeting critical infrastructure. Sygnia's investigation reveals that the attackers exploit trusted network infrastructure rather than traditional endpoints, allowing them to conceal their activities effectively. The operation has expanded beyond previous targets, indicating a shift in tactics toward more trusted systems. This activity is part of a broader trend of state-aligned cyber operations focusing on critical infrastructure. The attacks are ongoing, with evidence of AI integration in their workflows, although some AI efforts have resulted in false positives. The campaign's impact is significant, as compromised routers can facilitate lateral movement within networks, posing a severe risk to affected organizations.

Key Points: • Fire Ant targets Cisco IOS XR routers, compromising trusted infrastructure. • Linked to UNC3886, the campaign shows a shift in tactics toward trusted systems. • Evidence of AI integration in offensive workflows, with some limitations noted.

Ask AI about this cluster

Timeline

2014-09-24
CVE-2014-6271 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-02-21
Public exploit for CVE-2020-1938 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2022-03-30
Public exploit for CVE-2022-22965 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-09-03
CVE-2026-85046 published
A new vulnerability affecting Cisco devices was disclosed, with active exploitation confirmed shortly after.
Krypt3Ia.Wordpress
2026-09-04
CVE-2026-85046 added to CISA KEV
CISA added the newly published CVE to its Known Exploited Vulnerabilities catalog due to confirmed exploitation.
Krypt3Ia.Wordpress
2026-09-07
Escudodigital reports on Fire Ant
Escudodigital highlights the ongoing Fire Ant campaign targeting Cisco routers, emphasizing its espionage capabilities.
Escudodigital