Velvet Ant
Chinese state-sponsored (China-nexus, likely MSS or PLA-affiliated) · Espionage / long-duration intelligence collection
Tactics, Techniques & Procedures (TTPs)
- PAM backdoor: replacement of pam_unix.so with nine distinct malicious variants compiled in separate build environments, accepting a hardcoded backdoor password while harvesting legitimate user credentials
- OpenSSH trojanisation: replacement of ssh, sshd, and scp binaries with modified versions that log commands and capture credentials from every SSH session
- SOCKS5 proxy daemon masquerading as legitimate Samba service (smbd -D) for covert exfiltration and C2 traffic blending
- Air-gap bridging via SOCKS5 infrastructure — pivoting from internet-exposed hosts into physically isolated network segments
- F5 BIG-IP exploitation for initial access (2024 campaigns)
- PlugX and Cobalt Strike deployment for lateral movement in earlier-stage operations
- Long-duration stealth prioritised over operational tempo — decade-long persistence documented at one target
Known Targets
Analyst Notes
Sygnia disclosed Operation Highland in June 2026, revealing Velvet Ant persistence inside a target organisation from at least 2016 until discovery in 2026 — a decade-long undetected presence. The defining technique is surgical modification of the Linux authentication stack itself: backdoored PAM modules and OpenSSH binaries transform the authentication process into a credential-harvesting and persistent-access mechanism that survives most conventional remediation. Nine distinct pam_unix.so variants compiled in separate environments indicate a mature, operationally compartmentalised capability deployed across multiple engagements. The SOCKS5 masquerade technique (posing as smbd -D) and air-gap bridging capability indicate a group with both deep technical capability and deliberate operational security. Standard incident response — reimaging hosts, rotating credentials — does not remediate PAM-level backdoors unless specifically hunted for. Earlier Velvet Ant activity (2024) exploited F5 BIG-IP vulnerabilities for initial access before pivoting to authentication-layer persistence.
Also Known As