INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Chinese hackers hijack auth flow, spy on isolated network for 10 years

| 2026-06-12 18:17 CRITICAL MEDIUM
Executive Summary AI-generated
The Velvet Ant cyberespionage threat group has been active for over a decade, conducting sophisticated attacks on isolated critical infrastructure networks of large organizations. Their tactics have evolved significantly over time, with the most recent campaign dubbed "Operation Highland" beginning in 2016 and targeting vulnerable internet-facing systems before pivoting to an air-gapped environment. This campaign was attributed by Sygnia researchers who discovered it, highlighting the group's persistence and credential theft capabilities. The attack chain involves multiple vectors, including compromised internet-facing servers, reverse shell exploitation using GS-Netcat, and network traffic tunneling through custom SOCKS5 proxies. These tactics have been used in conjunction with authentication components such as PAM, OpenSSH, and Windows LSASS to establish a remote-execution path into the segregated environment. The Velvet Ant threat group's ability to adapt and evolve their tactics has allowed them to maintain persistence for extended periods, making them a significant concern for organizations worldwide.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent the use of malicious code, such as GS-Netcat reverse shells or custom SOCKS5 proxies. * Regularly update and patch Linux systems, including PAM modules and OpenSSH components, to ensure that known vulnerabilities are addressed before they can be exploited by threat actors like Velvet Ant. * Use secure authentication mechanisms, such as multi-factor authentication (MFA) or password policies with strong requirements, to prevent attackers from gaining unauthorized access to critical infrastructure networks. * Monitor network traffic for suspicious activity and implement intrusion detection systems (IDS) or firewalls to detect and block potential threats before they can be exploited by Velvet Ant or other threat actors.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation HighlandOperation Highland Velvet AntVelvet Ant CVE-2024-20399CVE-2024-20399
Target & Sectors
Global Scope
Incident Timeline
‎July 2024
Chinese hackers exploited a vulnerability in Cisco's authentication software and gained unauthorized access to an isolated network for nearly a decade.
‎Jun 12, 2026
Chinese hackers exploited a vulnerability in an isolated network to hijack its authentication flow and spy on users for over a decade.
‎2026/06/12
Chinese hackers hijack auth flow, spy on isolated network for a decade.
infrastructure Linux
organisation Linux / Network Security
threat_actor Velvet Ant
organisation PAM
organisation Operation Highland
organisation Sygnia
organisation Nexus
organisation GS
organisation Nginx
infrastructure Windows
organisation EDR
organisation MFA
organisation SSH
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product