logo

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

ID: 81047fc7-aa3d-5928-8e18-d7fee526d8f0

STIX ID: report--81047fc7-aa3d-5928-8e18-d7fee526d8f0

Feed Name: CosmicBytez Labs

Threat Score
92/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

...
...

Velvet Ant, a China-linked APT, maintained nearly a decade of access to enterprise Linux systems by backdooring PAM and OpenSSH to capture credentials, manipulate logs, and retain unnoticed access across updates. Sygnia's disclosure outlines the attack lifecycle (spearphishing/exploitation, replacement of authentication binaries, credential harvesting, and long-term persistence), highlights severe detection challenges, and provides detection and remediation guidance including binary integrity verification, expanded FIM coverage, credential rotation, and off-host authentication logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.