China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 Devices
ID: 2c50660b-09c7-58ba-9bd1-95936485794a
STIX ID: report--2c50660b-09c7-58ba-9bd1-95936485794a
Feed Name: The Hacker News
Threat Score
Sygnia attributed a multi‑year China-linked cyber espionage campaign dubbed "Velvet Ant" that compromised an East Asian organization, deployed PlugX backdoors, and abused out-of-date F5 BIG-IP appliances as covert internal C2 (via reverse SSH tunnels) to persist and exfiltrate sensitive customer and financial data; forensic analysis uncovered tools such as PMCD and a SOCKS tunneling utility (EarthWorm) and evidence of lateral movement using Impacket.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
