logo

Modified OpenSSH Binaries Let Velvet Ant Steal Passwords, Log Commands, and Hide Activity

ID: f80a7904-04d9-5ef8-957a-9c02afcea38b

STIX ID: report--f80a7904-04d9-5ef8-957a-9c02afcea38b

Feed Name: GBHackers

Threat Score
92/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

Sygnia’s Operation Highland uncovered a near-decade stealth campaign by Velvet Ant that replaced core authentication components (modified OpenSSH binaries and pam_unix.so variants) across multiple Linux environments to accept hardcoded backdoor passwords, harvest credentials, keylog interactive sessions, and persist through disguised systemd/SysV startup artifacts and a cloaked reverse shell (auditdb). The report details nine distinct pam variants, altered OpenSSH suite binaries, web/NGINX-based bridging into isolated IT-to-OT networks, forensic timelines dating to 2016, and prioritized detection and remediation recommendations including file-integrity monitoring, EDR, hardened jump hosts, and validated offline recovery images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.