logo

China's 'Velvet Ant' APT Nests Inside Multiyear Espionage Effort

ID: ec4fe990-3c46-5d22-9d82-195cac948fc1

STIX ID: report--ec4fe990-3c46-5d22-9d82-195cac948fc1

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-06-17

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers uncovered a multiyear Velvet Ant (China-linked) espionage campaign against a large East Asian company that achieved remarkable persistence by infecting legacy and unmonitored systems (including Windows Server 2003 and F5 Big‑IP appliances). The actor deployed PlugX RAT (with both external and internal C2 configurations), used Impacket/wmiexec for lateral movement, disabled EDR and erased logs, and created dormant fallback strongholds so that remediation efforts repeatedly failed to fully evict them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.