The Most Dangerous Intrusion Is the One That Turns the Alarms Off
most attackers break in and try not to get caught. this adversary breaks in, quietly disables the cameras, edits the security tapes, and moves into the walls of the building. that fire ant tradecraft.
fire ant, as tracked by sygnia, is a china-nexus espionage actor. a note on naming, because it matters. sygnia claims the activity strongly overlaps with unc3886, a chinese group google has tracked for years against virtualization and network gear. they stop short of a firm attribution because important technical differences remain. so this is china-nexus, high confidence, and probably in that unc3886 family, but not confirmed to a specific threat group yet.
you may remember fire ant from 2025, when it was burrowing into vmware esxi and vcenter, the virtualization layer. this new campaign is the evolution, and it is worse. they moved down into the plumbing. cisco routers. authentication servers. linux boxes managing the whole network. the devices nobody logs into daily, nobody patches often, and nobody watches closely.
here is how they got caught, and it tells you everything about their tradecraft. an investigator found a tunnel on a cisco router that should not exist. a gre tunnel interface, quietly moving traffic, with no configuration and no change history to explain how it got there. it was invisible in the historical data. the only reason anyone noticed is the tunnel itself was real even though every record of its creation had been erased.
erasing is the whole point. once inside the router, fire ant deployed custom malware running during odd-numbered hours and stopped during even-numbered hours. this apparently reduced continuous process visibility. it selectively suppressed syslog messages that could expose the activity, so the admins saw a cleaner version of reality than the router was actually living.
it changed file timestamps to poison the forensic trail. sygnia's own warning says do not trust the logs from compromised infrastructure, validate them against something else, because the attacker has been editing them. when you cannot trust your own records, you are not investigating an intrusion. you are reading a story the intruder wrote for you.
it went further. fire ant altered the command output administrators relied on to inspect the device, filtering what certain show commands returned so malicious tunnel configuration would disappear from view. the attacker was not just hiding activity. it was changing what the defenders themselves were allowed to see.
now understand why a router is the perfect prize. it is not the target. it is the vantage point. sitting on the device that routes and authenticates traffic, fire ant collected credentials and network data, mapped the trusted relationships between systems, captured traffic from multiple routers, and exported pcaps to external ftp infrastructure. that one box became a covert bridge to reach further. the initial victim may not have been the ultimate objective. it might have been a mere on-ramp.
sygnia says fire ant used that bridge to explore paths toward other high-value environments, including critical infrastructure. but the activity against those onward targets was scanning and connection attempts, not confirmed compromise. reconnaissance. they were casing the next building, not yet inside it. that distinction matters.
we spend enormous effort defending laptops and servers, the things with screens, edr, and antivirus. meanwhile the routers, the authentication servers, the management hosts, the connective tissue holding the network together, sit under-monitored and over-trusted. fire ant understands that better than most defenders. these systems are often outside normal endpoint detection and response coverage, and generate far less telemetry than the devices security teams watch every day. it does not want your data as much as it wants the position. control the infrastructure, and you control what everyone else can see, trust, and reach.
the scariest part is not that they got in. it is that on a compromised router, the logs told the admins everything was fine. the most dangerous intrusion is not the one setting off alarms. it is the one that reached in and quietly turned the alarms off.