China-Linked Hackers Compromise Cisco Routers and Logs

China-linked actors compromise Cisco routers and corrupt logging

China-linked hackers have recently targeted Cisco routers, compromising both device integrity and the reliability of on-device network logs. This cyber threat has serious implications for organisations that rely on Cisco equipment, particularly small and medium-sized businesses. The attackers’ tactics have undermined defenders’ ability to detect and respond to network intrusions, making awareness and prompt action critical.

China-Linked Attacks on Cisco Routers: What Happened?

Recent intelligence reports reveal that a threat group with links to China successfully compromised Cisco routers used in enterprise and government networks. The campaign appears to have begun in 2026, with attackers targeting routers running outdated or vulnerable software. This event has put a spotlight on the inherent risks in network infrastructure devices, which are often overlooked compared to endpoints or servers.

The attackers exploited unpatched vulnerabilities in Cisco IOS and IOS XE software, allowing them to gain privileged access to targeted routers. Once inside, the group was able to manipulate the routers’ core functions, including the logging mechanisms that are crucial for network monitoring and incident detection. The campaign reportedly targeted a range of models frequently deployed by small and medium-sized businesses, as well as some larger organisations.

  • When: Initial compromises were detected in 2026, with ongoing activity reported.
  • Who is affected: Organisations using vulnerable Cisco routers, especially SMBs with limited security resources.
  • Impacted products: Cisco routers running outdated IOS or IOS XE versions, specific models have not been publicly listed but are widely deployed in enterprise settings.

How the Attackers Bypassed Network Defences

The attackers used known and possibly zero-day vulnerabilities within Cisco router software to gain initial access. After exploiting these flaws, the hackers established persistent control over the devices. What sets this campaign apart is the manipulation of the network logs stored on the routers themselves. By altering or deleting log entries, the group made it extremely difficult for defenders to trace their activity or even confirm a compromise had occurred.

Security researchers have highlighted several steps in the attackers’ methodology:

  • Scanning for publicly accessible Cisco routers with outdated firmware.
  • Exploiting known vulnerabilities to gain administrative access.
  • Deploying custom scripts or commands to alter device configurations.
  • Erasing or modifying on-device network logs to obscure evidence of the intrusion.
  • Maintaining access for extended periods without detection.

This log manipulation greatly reduced the effectiveness of incident response processes. Investigators found that in many cases, security teams could not rely on device logs to reconstruct attacker actions. Forensic analysis was further complicated by the attackers’ ability to clean up after themselves, leaving few traces that could be discovered through standard monitoring techniques.

Timeline and Ongoing Exploitation Status

The first signs of this campaign appeared in 2026, following disclosures of vulnerabilities in Cisco router software. Reports indicate that exploitation is ongoing, with new compromises discovered recently. Cisco and third-party cybersecurity firms continue to monitor the situation and have issued advisories urging customers to apply patches and review network security controls.

Due to the stealthy nature of the attack and the tampering with network logs, many organisations may still be unaware that their routers have been compromised. Advanced persistent threat (APT) groups, such as those linked to China, are known for maintaining long-term access and using compromised devices as footholds for further attacks or espionage.

Security Implications of Compromised Network Logs

Network logs play a vital role in detecting suspicious activity, investigating breaches and demonstrating compliance. By making these logs unreliable, the attackers have struck at the heart of defenders’ visibility. Organisations that rely solely on on-device logs are at particular risk, as tampering can lead to missed alerts and delayed responses.

For small and medium-sized enterprises, the threat is especially acute. These organisations often lack dedicated security teams or advanced monitoring tools, making it easier for attackers to persist undetected. The incident highlights the importance of forwarding logs to secure, off-device collectors and regularly validating the integrity of those logs.

  • Reduced visibility into attacker activity or lateral movement
  • Increased risk of prolonged undetected compromise
  • Potential for attackers to use compromised routers as launch pads for wider campaigns

What Organisations Should Do Now

Given the ongoing nature of these attacks, organisations using Cisco routers should take immediate action:

  • Apply the latest security updates to all Cisco routers.
  • Review device configurations and access controls, limiting remote management where possible.
  • Forward all logs to a secure, centralised system off the device and regularly verify their integrity.
  • Conduct a thorough assessment to detect potential compromises, especially if relying on affected models or software versions.

Organisations should remain vigilant and consider that on-device logs may not reflect the true state of their network. Continued monitoring of Cisco advisories and threat intelligence feeds is recommended as the situation evolves.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call