logo

China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 Devices

ID: 2c50660b-09c7-58ba-9bd1-95936485794a

STIX ID: report--2c50660b-09c7-58ba-9bd1-95936485794a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-06-17

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Sygnia attributed a multi‑year China-linked cyber espionage campaign dubbed "Velvet Ant" that compromised an East Asian organization, deployed PlugX backdoors, and abused out-of-date F5 BIG-IP appliances as covert internal C2 (via reverse SSH tunnels) to persist and exfiltrate sensitive customer and financial data; forensic analysis uncovered tools such as PMCD and a SOCKS tunneling utility (EarthWorm) and evidence of lateral movement using Impacket.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.