logo

Velvet Ant’s Operation Highland: A Decade Inside Critical Infrastructure

ID: a9c1ccab-e447-5d32-a4ac-8e823b77db26

STIX ID: report--a9c1ccab-e447-5d32-a4ac-8e823b77db26

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Do Son

...
...

Operation Highland is a detailed incident report of a China-linked APT called Velvet Ant that remained stealthily embedded in a victim network for nearly a decade, ultimately reaching segregated critical infrastructure. The actors used multi-stage access chains (internet-facing persistence, lateral movement, HTTP-to-SSH bridging via compromised web servers), exploited vulnerabilities including a Cisco NX-OS zero-day, deployed custom backdoors (VELVETSHELL), trojanized PAM and OpenSSH binaries to capture credentials and maintain persistence, and employed high operational security to avoid detection; the report highlights the difficulty of remediation and recommends treating authentication components as critical assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.