A China-linked hacking group secretly controlled a large organization's critical infrastructure network for a decade, even after the sensitive environment was separated from the internet. Sygnia attributes the campaign, called Operation Highland, to Velvet Ant, which first compromised internet-facing systems and then built an execution path into the isolated network by altering Nginx and FastCGI (a web-server request handler) configurations. The attackers used modified GS-Netcat and SOCKS5 tools for access and pivoting, then replaced Linux PAM authentication modules and OpenSSH components with trojanized versions to backdoor logins, steal credentials, and record administrator commands.
Why it matters: This is notable because it shows a sophisticated state-linked actor quietly maintaining access to critical systems for years by tampering with core login and remote-access components. Organizations running Linux in segmented or industrial environments should hunt for altered PAM, OpenSSH, Nginx, and startup-service files and review long-term credential exposure and administrative access.
SecurityWeek News
2026.06.19
75% relevant
The article summarizes the same Velvet Ant intrusion, including long-term access since around 2016, use of backdoored PAM/OpenSSH, proxies, and credential theft in a segregated network.
Bill Toulas
2026.06.13
100% relevant
This article establishes a distinct espionage story centered on Velvet Ant's newly detailed Operation Highland intrusion chain and decade-long persistence inside an isolated critical infrastructure environment; it is not the same underlying event as the existing tracked Velvet Ant-related items.
← Back to all stories