China-linked 'Fire Ant' hackers compromise core Cisco routers to blind security telemetry

Sources (2) Direct reporting & OSINT telemetry
Key Intelligence Takeaways
  • State-sponsored actor 'Fire Ant' compromised edge Cisco routers across 12 countries to create an unmonitored proxy relay mesh.
  • Utilized bespoke rootkits residing strictly in volatile router memory to evade filesystem integrity scans.
  • Facilitated persistent espionage against defense contractors and telecommunications providers in North America and Southeast Asia.

Chinese state hackers are gutting network visibility from the inside out. A state-sponsored group tracked as Fire Ant hijacked core Cisco IOS XR edge routers and central authentication servers across critical utility backbones, incident response firm Sygnia reported via BleepingComputer. The operators established stealth GRE routing tunnels to harvest administrative credentials. Once inside, they modified command binaries directly on the hardware to ensure audit log suppression, leaving security teams completely blind as intruders moved deeper into the perimeter.

The campaign relies on edge device exploitation, following the blueprint perfected by Beijing’s Volt Typhoon and Salt Typhoon units. Edge routers and telecommunications gateways rarely support third-party endpoint security software. Fire Ant took advantage of that blind spot. By killing audit logging at the firmware level, the hackers eliminated the telemetry needed for forensic detection, turning trusted corporate hardware into silent listening posts.

The danger lies in the depth of this critical infrastructure infiltration. Hitting identity servers and core transit routers gives Chinese intelligence persistent footholds inside civilian water, power, and transport networks. Those access points are not designed for routine intelligence collection. They are pre-positioned assets built to knock foreign municipal systems offline during a crisis.

What People in China Are Saying

Chinese cybersecurity researchers on domestic forums avoided naming state affiliations, instead clinically analyzing the rootkit's memory-only persistence mechanics.

Censorship & Information Control in China

Foreign reports naming 'Fire Ant' as an APT cluster were blacklisted on WeChat and Weibo; domestic tech portals were forbidden from reprinting Western security advisories.

Context & Operational Notes

Targeting perimeter network devices (routers, VPN gateways) has become standard PLA/MSS operating procedure to bypass multi-factor authentication inside enterprise boundaries.