logo

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

ID: 5e6cde09-2c97-584d-8058-88459149ee50

STIX ID: report--5e6cde09-2c97-584d-8058-88459149ee50

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

Author: [email protected] (The Hacker News)

...
...

Velvet Ant, a China-nexus threat actor, covertly backdoored Linux login components (PAM and OpenSSH) since 2016 to log credentials and commands and maintain persistent access to isolated networks by staging through internet-facing systems; the group has also abused F5 and Cisco infrastructure. The report recommends integrity monitoring of login binaries, comparing against known-good copies, removing backdoors prior to password resets, patching relevant CVEs (including CVE-2024-20399), and testing replacements in a lab to avoid administrator lockout.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.