logo

RST TI Report Digest: 15 Jun 2026

ID: e5b89ef7-0d2e-589e-8378-9cc6a5917d46

STIX ID: report--e5b89ef7-0d2e-589e-8378-9cc6a5917d46

Feed Name: RST Cloud Blog

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: RST Cloud

...
...

Sygnia’s investigation of Operation Highland attributes a decade-long, highly sophisticated intrusion in a critical infrastructure environment to a China-nexus actor dubbed Velvet Ant. The actor initially compromised Internet-facing systems, pivoted into an isolated operational network, backdoored authentication components (multiple pam_unix.so variants and modified OpenSSH binaries) to capture credentials, bypass logging, and persist despite password changes, and deployed custom tools including a modified GS-Netcat reverse shell and an Nginx/FastCGI execution bridge; the report includes extensive IOCs (IPs, domains, and many file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.