China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
ID: 5e6cde09-2c97-584d-8058-88459149ee50
STIX ID: report--5e6cde09-2c97-584d-8058-88459149ee50
Feed Name: The Hacker News
Velvet Ant, a China-nexus threat actor, covertly backdoored Linux login components (PAM and OpenSSH) since 2016 to log credentials and commands and maintain persistent access to isolated networks by staging through internet-facing systems; the group has also abused F5 and Cisco infrastructure. The report recommends integrity monitoring of login binaries, comparing against known-good copies, removing backdoors prior to password resets, patching relevant CVEs (including CVE-2024-20399), and testing replacements in a lab to avoid administrator lockout.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
