Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
ID: d62b7bc3-fd17-52b0-b078-829136f9f597
STIX ID: report--d62b7bc3-fd17-52b0-b078-829136f9f597
Feed Name: ThreatCluster
Threat Score
Operation Highland was a sophisticated, decade-long cyberespionage campaign by the Velvet Ant group that exploited a Cisco NX-OS zero-day (CVE-2024-20399) and a modified GS-Netcat reverse shell to gain remote execution, pivot into an air-gapped critical infrastructure network, maintain long-term persistence, and steal administrative credentials; investigations are ongoing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
