Chinese hackers hijack auth flow, spy on isolated network for a decade
ID: e28a0d19-8e01-5f46-b549-ae526aae31f3
STIX ID: report--e28a0d19-8e01-5f46-b549-ae526aae31f3
Feed Name: Bleeping Computer
Sygnia describes 'Operation Highland', a long-running intrusion by the Velvet Ant APT that breached internet-facing servers in 2016 and, via custom proxies and an Nginx/FastCGI execution bridge, achieved remote execution inside an air-gapped critical-infrastructure network. The adversary deployed modified GS-Netcat shells, a custom SOCKS5 proxy, and trojanized authentication components (backdoored pam_unix.so and OpenSSH binaries) to harvest credentials and observe all administrative activity, creating highly persistent access that was difficult and risky to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
