Activity timeline
Velvet Ant appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.
ATT&CK techniques observed
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 2 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
- T1021.004 SSH — Lateral Movementobserved in 2 of 3 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1056.001 Keylogging — Credential Accessobserved in 2 of 3 tracked threats
- T1059.004 Unix Shell — Executionobserved in 2 of 3 tracked threats
- T1070.006 Timestomp — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1098.004 SSH Authorized Keys — Persistenceobserved in 2 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 3 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 2 of 3 tracked threats
- T1543.002 Systemd Service — Persistenceobserved in 2 of 3 tracked threats
- T1554 Compromise Host Software Binary — Persistenceobserved in 2 of 3 tracked threats
Tracked threats
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for Decade-Long Credential Theft in an Isolated NetworkHIGH
- Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage PersistenceCRITICAL