Velvet Ant’s Operation Highland: A Decade Inside Critical Infrastructure
ID: a9c1ccab-e447-5d32-a4ac-8e823b77db26
STIX ID: report--a9c1ccab-e447-5d32-a4ac-8e823b77db26
Feed Name: securityonline.info
Operation Highland is a detailed incident report of a China-linked APT called Velvet Ant that remained stealthily embedded in a victim network for nearly a decade, ultimately reaching segregated critical infrastructure. The actors used multi-stage access chains (internet-facing persistence, lateral movement, HTTP-to-SSH bridging via compromised web servers), exploited vulnerabilities including a Cisco NX-OS zero-day, deployed custom backdoors (VELVETSHELL), trojanized PAM and OpenSSH binaries to capture credentials and maintain persistence, and employed high operational security to avoid detection; the report highlights the difficulty of remediation and recommends treating authentication components as critical assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
