Security1 distinct publisher3 min readPublished
Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Sygnia found a component on the router that embedded a modified system library, checked each outgoing log message for the string Health, and forwarded it only when the string was present [8]. A collector watching that device does not fall silent. It keeps receiving healthy-looking messages from a live host while everything else is dropped at the source, which means the router's own syslog stream is worthless as evidence of the router's state.
The second layer targeted the operator rather than the collector. A separate component altered the command-execution path to append an `| exclude` filter to show commands, so an administrator inspecting the device saw a configuration with the attacker's tunnel edited out [9].
That matters for how the intrusion surfaced. The anomaly was a GRE tunnel interface operating with no running configuration and no commit history to explain its creation [6]. A change-control review reads commits. This tunnel had none, so nothing in the change record would have shown it; catching it required comparing observed interface state against configuration [17]. Sygnia did not identify how the actor first gained access to the router [7].
On the TACACS server, an injector named acppid loaded a malicious library into the running tac_plus process, hooked the functions that accept new connections, and passed live session handles to a second process over a local Unix socket [11]. Captured credentials went to `/var/log/.tacplus.acct`, obfuscated with a single-byte XOR key of 0xEF [12]. A single byte is 256 possible keys, so that file costs a responder nothing to decode once located; the obfuscation slows down a casual keyword search but not a real one [18]. Sygnia says this specific tac_plus library-injection technique has not been publicly described before [13], though Mandiant has documented UNC3886 deploying a TACACS+ sniffer called LOOKOVER and replacing the tac_plus daemon with a backdoored version [14].
Attribution is stated carefully in the report and should be repeated that way. Sygnia assesses strong overlap with public reporting on UNC3886 but does not make a conclusive attribution [4]. Mandiant, which first documented UNC3886, found no technical overlap with Salt Typhoon or Volt Typhoon [5]. The activity sits outside the Typhoon campaigns.
Egress is where the collection became traffic. Packet captures from multiple Cisco devices were uploaded to external FTP servers, one of which appeared to have been installed the same day the uploads took place [10]. Infrastructure with a one-day life is only caught by flow records that outlive it.
The concealment spanned five mechanisms: the syslog filter, the show-command exclusion, BridgeAgent posing as a Zabbix agent under a `zabbix_agent.service` systemd unit with its process disguised as `/usr/bin/gnome-shell` [15], the Medusa and REPTILE rootkits on the Linux management hosts [16], and the dotfile credential store. Four of those five sit below or beside the tooling most estates use to watch these hosts [19].
The reach claim stays bounded. Sygnia assessed the actor explored paths toward connected high-value environments including critical infrastructure, but activity there was limited to scanning and connection attempts, not confirmed compromise [3]. From the legacy Linux host reached through the tunnel, that probing hit SSH, HTTP, SMB and RDP on connected networks [20].
Ranked by verification strength, evidence, and original report placement.
Fire Ant, a China-nexus cyber espionage actor, expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts used to route, authenticate and manage high-value networks.
Sygnia, the incident response firm that investigated the intrusion, said the actor turned compromised routers into collection platforms, capturing network traffic, harvesting credentials and suppressing logging and telemetry defenders rely on to reconstruct an attack.
Sygnia assessed the group used its foothold to explore paths to connected high-value environments including critical infrastructure, but activity against those networks was limited to scanning and connection attempts rather than confirmed compromise.
Sygnia assessed the activity strongly overlaps with public reporting on UNC3886, a China-nexus espionage group known for targeting virtualization platforms and network edge devices, but said its report does not make a conclusive attribution.
Mandiant, which first documented UNC3886, has said it found no technical overlap between that group and the separate Chinese operations tracked as Salt Typhoon and Volt Typhoon.
The investigation began with an anomaly on a Cisco IOS XR router, where a Generic Routing Encapsulation (GRE) tunnel interface was operating with no running configuration or commit history to explain how it had been created.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
security
Snowflake's passwordless deadline turns Moucka-era credential debt into a due-dated cleanup1 distinct publisher
security
Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.1 distinct publisher
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Forensically granular, institutionally singular
Claims this specific are hard to fake and easy to check — a named injector binary with a hash, a credential file at a given path decoded with one byte, a service unit name — and the reporting is candid where the record is empty, saying outright that initial access was never established. What it cannot offer is a second pair of eyes: the observations, the tool names and the actor name all originate with the firm that was hired to investigate.
One engagement, victims unnamed
Breadth is asserted but never sized. Packet captures came from multiple Cisco devices and some implants were planted in 2025 then reused a year later, which points to a persistent operation rather than a one-off, but the reporting names no victim, no sector, no country and no device count, and the traffic toward critical-infrastructure networks amounted to scanning and connection attempts. The July 2025 hypervisor disclosure is the only evidence that this is a continuing campaign rather than a single case file.
Caveats kept, stakes undersold
The restraint is real: no confirmed compromise of critical infrastructure, no conclusive attribution, no known entry point, and Mandiant's separation of UNC3886 from the Typhoon clusters is included rather than blurred into a scarier whole. If anything the framing understates what is on the page — five separate concealment layers across three tiers, and a credential store for the entire estate quietly hooked in memory, is a harder finding than 'hijacks routers, blinds logs' conveys.
The investigator owns the vocabulary
Fire Ant, TacTap, BridgeAgent — the actor and both new tools carry names Sygnia coined, and the firm is also the source of the claim that its own find has never been publicly described. That is how threat intelligence works, and the artifacts stand on their own, but it means the story's novelty, its naming and its severity are all authored by the party whose credibility the report advertises. The closing advice that routers, TACACS servers, hypervisors and jump hosts deserve first-class forensic treatment is, not incidentally, a description of the work.
Trust the artifacts, not the perimeter
Confidence tracks the specificity, and drops for everything the specificity cannot reach. The hashes, paths and hooks would be strange things to invent and are independently checkable. The missing entry vector, the unnamed victim, the truncated indicator list and the absence of any second account mean the shape of the campaign, and how much of anyone's estate it touches, remains this firm's telling.