logo

China-linked spies backdoored authentication stack to stay hidden for years

ID: be2a5393-0a58-5874-92cb-aec7c336e863

STIX ID: report--be2a5393-0a58-5874-92cb-aec7c336e863

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: Zeljka Zorz

...
...

Sygnia reports that a China-linked APT known as Velvet Ant maintained nearly a decade of stealthy access to an unnamed organization by using modified GS-Netcat, a custom SSH-triggered binary, a SOCKS5 proxy, backdoored pam_unix.so modules and OpenSSH binaries that captured credentials, logged commands, and appended persistent keys to authorized_keys; the multi-layered compromise of the authentication stack made detection and eradication highly complex and risky for production systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.