Researchers tracking Fire Ant found an active GRE tunnel interface on a Cisco IOS XR router that no running configuration explained, the kind of artifact that only exists if someone built it outside the audit trail designed to catch it. The group had already pivoted off a VMware hypervisor campaign into TACACS+ authentication systems, meaning the same intrusion that hijacked the routing plane also touched the system deciding who gets administrative access to it. Two footholds, one operator. Cisco's advisories on IOS XR describe hardening steps. Neither one covers a GRE tunnel with no corresponding config line, because that's not a configuration weakness, it's a logging integrity failure.
The control that would have changed this outcome is configuration drift detection independent of the device's own logs, something that diffs running state against a known-good baseline rather than trusting the router to report on itself. Fire Ant's move only works because the router is both the compromised asset and the sole witness. For a network operations team, the fix isn't a patch, it's a second source of truth that doesn't live on the box Fire Ant already owns. Cisco has not published a CVE tied to this specific GRE tunnel technique as of September 1, 2026.