Velvet Ant
[Velvet Ant](https://attack.mitre.org/groups/G1047) is a threat actor operating since at least 2021. [Velvet Ant](https://attack.mitre.org/groups/G1047) is associated with complex persistence mechanisms, the targeting of…
[Velvet Ant](https://attack.mitre.org/groups/G1047) is a threat actor operating since at least 2021. [Velvet Ant](https://attack.mitre.org/groups/G1047) is associated with complex persistence mechanisms, the targeting of…
Sygnia, tracking the China-nexus group as Velvet Ant, discovered that the group backdoored Linux PAM and OpenSSH components to maintain persistent access…
CVE-2024-20399 is a vulnerability in Cisco NX-OS that requires admin access and was exploited by the China-linked group Velvet Ant to plant…
Velvet Ant, tracked by Sygnia, is a China-nexus threat actor known for targeting infrastructure components like F5 BIG-IP, Cisco NX-OS, and Linux…
Operation Highland is a campaign by the China-linked Velvet Ant group that backdoored Linux PAM and OpenSSH components to maintain persistent access…