Fire Ant TacTap and BridgeAgent malware activity on IOS XR and Linux hosts
Malware Activity
Summary
Hide ▲
Show ▼
The Fire Ant toolset added TacTap credential collection and a BridgeAgent Linux backdoor to its router-focused intrusion set, extending persistent access across Cisco IOS XR and Linux management hosts and increasing the risk of credential theft and packet capture.
Related Happenings
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware Activity
H score31
First: 12.02.2026 16:25
Last: 12.02.2026 16:25
Sources 1
About this happening:
Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...
Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware ActivityAbout this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...
MacOS infostealer campaign using fake ads and ClickFix lures
Campaign
H score41
First: 04.02.2026 09:42
Last: 04.02.2026 09:42
Sources 1
About this happening:
macOS users are being targeted in a ClickFix campaign that abuses Google search ads to steer people into poisoned ChatGPT and Grok conversations. The lure uses...
MacOS infostealer campaign using fake ads and ClickFix lures
CampaignAbout this happening: macOS users are being targeted in a ClickFix campaign that abuses Google search ads to steer people into poisoned ChatGPT and Grok conversations. The lure uses...
Timeline
-
31.08.2026 12:04 2 articles · 2h ago
Fire Ant extends into Cisco IOS XR routers and TACACS servers
Initial DisclosureSygnia disclosed a 2026 intrusion in which Fire Ant extended a long-running campaign beyond VMware hypervisors into Cisco IOS XR routers, TACACS servers, and Linux management hosts, using compromised routers to capture packet data, harvest credentials, and suppress logging and telemetry while deploying TacTap on TACACS systems and BridgeAgent on a tunnel-connected Linux host. The firm assessed overlap with UNC3886 reporting but did not make a conclusive attribution.
Show sources
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs — thehackernews.com — 31.08.2026 12:04
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs — thehackernews.com — 31.08.2026 12:04