Sygnia reported that the China-linked threat group Velvet Ant maintained covert access to an organization's network for nearly a decade by modifying trusted Linux authentication components in an intrusion campaign dubbed Operation Highland. Instead of relying on conventional malware, the attackers backdoored PAM and OpenSSH to bypass authentication with a secret password, steal legitimate credentials, and log commands while blending in with normal administrative activity. Researchers identified nine distinct versions of the tampered software, indicating the operation evolved over years and that the earliest observed activity dates back to 2016.
The intrusion reportedly reached an air-gapped or otherwise isolated environment by staging through internet-facing systems and using a web server as a bridge into the segmented network. Sygnia said the case shows why patching and password resets alone are insufficient when trusted login binaries have been altered, and urged defenders to verify the integrity of PAM and OpenSSH files against known-good copies, remove backdoors before resetting credentials, and monitor or patch related edge infrastructure. The tradecraft aligns with Velvet Ant's broader pattern of hiding in trusted systems, including prior activity involving F5 BIG-IP devices and exploitation of CVE-2024-20399 on Cisco NX-OS switches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Sygnia disclosed that Velvet Ant replaced legitimate Linux PAM modules, including pam_unix.so, with trojanized versions that allowed authentication bypass via a hardcoded password and harvested credentials from normal logins. The report also described additional persistence through a disguised GS-Netcat binary, systemd and SysVinit mechanisms, and appended SSH authorized_keys entries.
Sygnia disclosed that Velvet Ant maintained stealthy persistence for nearly a decade by modifying trusted Linux login binaries rather than deploying conventional malware. The researchers said the attackers used internet-facing systems and a web server as a bridge into an air-gapped or isolated environment, and identified multiple tampered software versions.
Sygnia said Velvet Ant's tradecraft matched prior 2024 incidents involving persistence on F5 BIG-IP appliances and exploitation of Cisco NX-OS vulnerability CVE-2024-20399 on switches. The linkage was cited as part of the group's broader pattern of hiding in trusted infrastructure.
Sygnia reported that the earliest observed activity in Velvet Ant's Operation Highland dates to 2016. The China-linked group established long-term access by backdooring Linux PAM and OpenSSH components inside an isolated network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.