China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
ID: 81047fc7-aa3d-5928-8e18-d7fee526d8f0
STIX ID: report--81047fc7-aa3d-5928-8e18-d7fee526d8f0
Feed Name: CosmicBytez Labs
Velvet Ant, a China-linked APT, maintained nearly a decade of access to enterprise Linux systems by backdooring PAM and OpenSSH to capture credentials, manipulate logs, and retain unnoticed access across updates. Sygnia's disclosure outlines the attack lifecycle (spearphishing/exploitation, replacement of authentication binaries, credential harvesting, and long-term persistence), highlights severe detection challenges, and provides detection and remediation guidance including binary integrity verification, expanded FIM coverage, credential rotation, and off-host authentication logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
