Velvet Ant Hackers Backdoor OpenSSH and PAM to Spy on Critical Infrastructure Network
ID: 78da1aaf-1ec4-5691-9d4a-f4bf7bd52dea
STIX ID: report--78da1aaf-1ec4-5691-9d4a-f4bf7bd52dea
Feed Name: GBHackers
**Operation Highland (Velvet Ant):** A near-decade, highly disciplined intrusion in which a China-linked APT replaced core authentication components (backdoored pam_unix.so variants and modified OpenSSH binaries), deployed custom C2 (modified GS‑Netcat, SOCKS5 proxy), and abused web/FastCGI to pivot into segmented critical-infrastructure hosts; the report highlights credential exfiltration, persistent access that survives normal containment, and complex remediation steps (per-host testing, golden recovery hosts, vaulting credentials) to safely restore affected environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
