Modified OpenSSH Binaries Let Velvet Ant Steal Passwords, Log Commands, and Hide Activity
ID: f80a7904-04d9-5ef8-957a-9c02afcea38b
STIX ID: report--f80a7904-04d9-5ef8-957a-9c02afcea38b
Feed Name: GBHackers
Sygnia’s Operation Highland uncovered a near-decade stealth campaign by Velvet Ant that replaced core authentication components (modified OpenSSH binaries and pam_unix.so variants) across multiple Linux environments to accept hardcoded backdoor passwords, harvest credentials, keylog interactive sessions, and persist through disguised systemd/SysV startup artifacts and a cloaked reverse shell (auditdb). The report details nine distinct pam variants, altered OpenSSH suite binaries, web/NGINX-based bridging into isolated IT-to-OT networks, forensic timelines dating to 2016, and prioritized detection and remediation recommendations including file-integrity monitoring, EDR, hardened jump hosts, and validated offline recovery images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
