The Chinese cyberespionage group Velvet Ant maintained undetected access to a critical infrastructure network for ten years by compromising authentication stacks and pivoting into isolated, air-gapped systems.
Key Points
- Researchers at Sygnia discovered "Operation Highland," a decade-long espionage campaign targeting a large organization's isolated network.
- Velvet Ant gained initial access via internet-facing servers before using custom SOCKS5 proxies to tunnel into air-gapped environments.
- The attackers achieved long-term persistence by replacing legitimate Linux PAM and OpenSSH components with backdoored versions to harvest credentials.
- Nine distinct variants of malicious PAM modules were identified, allowing the group to bypass authentication and monitor all administrative activity.
- Remediation proved highly complex, requiring researchers to build a testing lab to prevent operational outages during the removal of trojanized system files.