RST TI Report Digest: 15 Jun 2026
ID: e5b89ef7-0d2e-589e-8378-9cc6a5917d46
STIX ID: report--e5b89ef7-0d2e-589e-8378-9cc6a5917d46
Feed Name: RST Cloud Blog
Sygnia’s investigation of Operation Highland attributes a decade-long, highly sophisticated intrusion in a critical infrastructure environment to a China-nexus actor dubbed Velvet Ant. The actor initially compromised Internet-facing systems, pivoted into an isolated operational network, backdoored authentication components (multiple pam_unix.so variants and modified OpenSSH binaries) to capture credentials, bypass logging, and persist despite password changes, and deployed custom tools including a modified GS-Netcat reverse shell and an Nginx/FastCGI execution bridge; the report includes extensive IOCs (IPs, domains, and many file hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
