Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fire Ant TacTap and BridgeAgent malware activity on IOS XR and Linux hosts

Malware Activity
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

The Fire Ant toolset added TacTap credential collection and a BridgeAgent Linux backdoor to its router-focused intrusion set, extending persistent access across Cisco IOS XR and Linux management hosts and increasing the risk of credential theft and packet capture.

Related Happenings

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse

Malware Activity
H score31 First: 12.02.2026 16:25 Last: 12.02.2026 16:25 Sources 1

About this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...

MacOS infostealer campaign using fake ads and ClickFix lures

Campaign
H score41 First: 04.02.2026 09:42 Last: 04.02.2026 09:42 Sources 1

About this happening: macOS users are being targeted in a ClickFix campaign that abuses Google search ads to steer people into poisoned ChatGPT and Grok conversations. The lure uses...

Timeline

  1. 31.08.2026 12:04 2 articles · 2h ago

    Fire Ant extends into Cisco IOS XR routers and TACACS servers

    Initial Disclosure

    Sygnia disclosed a 2026 intrusion in which Fire Ant extended a long-running campaign beyond VMware hypervisors into Cisco IOS XR routers, TACACS servers, and Linux management hosts, using compromised routers to capture packet data, harvest credentials, and suppress logging and telemetry while deploying TacTap on TACACS systems and BridgeAgent on a tunnel-connected Linux host. The firm assessed overlap with UNC3886 reporting but did not make a conclusive attribution.

    Show sources