AUTO-UPDATED

Chinese hackers hijack auth flow, spy on isolated network for a decade

The Chinese cyberespionage group Velvet Ant maintained undetected access to a critical infrastructure network for ten years by compromising authentication stacks and pivoting into isolated, air-gapped systems.

Key Points

  • Researchers at Sygnia discovered "Operation Highland," a decade-long espionage campaign targeting a large organization's isolated network.
  • Velvet Ant gained initial access via internet-facing servers before using custom SOCKS5 proxies to tunnel into air-gapped environments.
  • The attackers achieved long-term persistence by replacing legitimate Linux PAM and OpenSSH components with backdoored versions to harvest credentials.
  • Nine distinct variants of malicious PAM modules were identified, allowing the group to bypass authentication and monitor all administrative activity.
  • Remediation proved highly complex, requiring researchers to build a testing lab to prevent operational outages during the removal of trojanized system files.

Why it Matters

This breach highlights the severe risks posed by sophisticated actors who embed themselves directly into core authentication processes to bypass standard security measures. Organizations must prioritize file integrity monitoring and hardened access controls to protect critical system components from such deep-seated, long-term persistence.
BleepingComputer Published by Bill Toulas
Read original