China-linked spies backdoored authentication stack to stay hidden for years
ID: be2a5393-0a58-5874-92cb-aec7c336e863
STIX ID: report--be2a5393-0a58-5874-92cb-aec7c336e863
Feed Name: Help Net Security
Sygnia reports that a China-linked APT known as Velvet Ant maintained nearly a decade of stealthy access to an unnamed organization by using modified GS-Netcat, a custom SSH-triggered binary, a SOCKS5 proxy, backdoored pam_unix.so modules and OpenSSH binaries that captured credentials, logged commands, and appended persistent keys to authorized_keys; the multi-layered compromise of the authentication stack made detection and eradication highly complex and risky for production systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
