Skip to main content
Promotional banner for the pentest readiness checklist
Endpoint Security Won't Save You From Infrastructure ThreatsCyber Threats & Attacks
4 min readFor Chief Information Security Officers (CISOs)

Endpoint Security Won't Save You From Infrastructure Threats

The Conventional Wisdom

You might think your security stack is a fortress. You've deployed EDR on every laptop, secured your cloud workloads, trained your users on phishing, and tuned your SIEM to catch anomalies. When considering threat actors, you likely picture them targeting endpoints, exploiting user credentials, or finding misconfigurations in your AWS environment.

Network infrastructure? That's just the plumbing. Routers authenticate, route packets, and mostly just work. You patch them when the vendor releases updates. You might have segmented your network. But you don't monitor router logs like you do endpoint activity, and you certainly don't treat your Cisco IOS XR devices as high-priority forensic assets during an incident response.

This assumption is leaving organizations vulnerable.

The Overlooked Threat

The endpoint-centric security model mistakenly treats routers, hypervisors, and TACACS servers as mere support infrastructure rather than potential attack surfaces. This oversight can have serious consequences.

When Sygnia tracked the Fire Ant campaign (linked to the group Mandiant calls UNC3886), they found attackers who'd bypassed endpoints entirely. These actors targeted Cisco IOS XR routers as the primary objective. Once inside, they captured traffic from multiple routers, uploaded data to external infrastructure, and used their position to observe interactions among systems, administrators, and connected networks.

Compromising a router gives attackers perspective, not just reach. They can see authentication patterns across your environment, watch administrators work, and identify which credentials unlock access to third-party networks. There's no need to install malware on every endpoint when they control the infrastructure connecting them.

The Fire Ant actors also compromised TACACS servers, which authenticate administrative users and authorize commands. By controlling this layer, they harvested credentials in real time, creating ambiguity between legitimate administrative activity and malicious commands. Their presence became nearly indistinguishable from normal operations.

The Evidence

Sygnia's research shows threat actors building custom malware specifically to control routers and modify them for persistent access. The attackers didn't stop at one compromise. They established network vantage points across environments, gaining visibility into how trust relationships actually function, not how they're documented in your network diagrams.

Their sophistication extends to evidence manipulation. Fire Ant actors hid logs, deleted files, and tampered with firewall rules to conceal their activity. They understood that most security teams lack the forensic tools or procedures to investigate router compromises with the same rigor they apply to endpoint incidents.

This isn't an isolated pattern. Chinese state-backed groups have repeatedly targeted Cisco infrastructure. Volt Typhoon focused on end-of-life Cisco routers and network devices in the U.S., U.K., and Australia. Salt Typhoon compromised more than 1,000 Cisco network devices. Between September and December 2025, defenders warned repeatedly about attacks on Cisco Adaptive Security Appliances.

The common thread: these devices sit outside the coverage of most security tools. They don't trigger alerts and are assumed to be trustworthy by design.

What to Do Instead

Start by treating routers, hypervisors, and authentication infrastructure as first-class security assets. That means three operational changes:

First, build forensic readiness into your infrastructure layer. You need logging that captures administrative activity on routers and TACACS servers. Retain these logs long enough to detect long-dwell compromises. Develop the capability to analyze router memory and configuration files during an incident, not just endpoint disk images.

If your incident response runbook doesn't include procedures for investigating router compromises, you're not ready for this threat.

Second, implement continuous validation of trust relationships. Don't rely on periodic checks of network infrastructure. Continuously monitor authentication patterns, command execution, and configuration changes on devices that create trust and reachability across your environment.

This monitoring should answer specific questions: Which administrative accounts are accessing routers from which systems? Are commands being executed that modify logging or firewall rules? Are there unusual patterns in how credentials are being used across your TACACS infrastructure?

Third, segment your security monitoring strategy by infrastructure type. Your EDR alerts won't catch router compromises. Your cloud security posture management tools won't see TACACS credential harvesting. You need visibility tools and detection logic purpose-built for network infrastructure, not repurposed from endpoint security.

This isn't about buying new products. It's about acknowledging that different attack surfaces require different defensive approaches.

When the Conventional Wisdom Is Right

Endpoint security still matters enormously. Most breaches start with phishing, credential theft, or exploited vulnerabilities on user devices. Your investment in EDR, identity protection, and user training remains essential.

The conventional focus on endpoints is right when defending against commodity ransomware, opportunistic attacks, and threats that rely on user interaction. These actors need a foothold on a workstation before they can move laterally.

Endpoint-centric security is also correct when dealing with resource constraints. If you're a mid-market organization without dedicated infrastructure security staff, hardening endpoints and implementing basic network segmentation will stop more attacks than sophisticated router monitoring.

But if you're operating critical infrastructure, managing networks that connect to high-value third parties, or defending against sophisticated state-backed groups, the endpoint-only model leaves you blind to how these actors actually operate.

The Fire Ant campaign shows that advanced threat actors have shifted their focus to the infrastructure that sits between environments. They're targeting the systems that create trust, reachability, and visibility because compromising those systems gives them perspective across your entire environment.

Your security model needs to account for that reality. Routers aren't plumbing. They're attack surfaces that require monitoring, hardening, and incident response readiness. Treat them accordingly.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like