China-linked Velvet Ant hijacked Linux authentication and spied on an isolated critical infrastructure network for 10 years

A China-linked hacking group secretly controlled a large organization's critical infrastructure network for a decade, even after the sensitive environment was separated from the internet. Sygnia attributes the campaign, called Operation Highland, to Velvet Ant, which first compromised internet-facing systems and then built an execution path into the isolated network by altering Nginx and FastCGI (a web-server request handler) configurations. The attackers used modified GS-Netcat and SOCKS5 tools for access and pivoting, then replaced Linux PAM authentication modules and OpenSSH components with trojanized versions to backdoor logins, steal credentials, and record administrator commands.
Why it matters: This is notable because it shows a sophisticated state-linked actor quietly maintaining access to critical systems for years by tampering with core login and remote-access components. Organizations running Linux in segmented or industrial environments should hunt for altered PAM, OpenSSH, Nginx, and startup-service files and review long-term credential exposure and administrative access.

Sources

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
SecurityWeek News 2026.06.19 75% relevant
The article summarizes the same Velvet Ant intrusion, including long-term access since around 2016, use of backdoored PAM/OpenSSH, proxies, and credential theft in a segregated network.
Chinese hackers hijack auth flow, spy on isolated network for a decade
Bill Toulas 2026.06.13 100% relevant
This article establishes a distinct espionage story centered on Velvet Ant's newly detailed Operation Highland intrusion chain and decade-long persistence inside an isolated critical infrastructure environment; it is not the same underlying event as the existing tracked Velvet Ant-related items.
← Back to all stories