news.mlab.sh
Threat intelligence
Threat actor

Velvet Ant

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
Targeted countries
China
TLP
WHITE

(Sygnia) Velvet Ant is a sophisticated and innovative threat actor. The investigation confirmed the threat actor maintained a prolonged presence in the organization’s on–premises network for about three years. The overall goal behind this campaign was to maintain access to the target network for espionage. The threat actor achieved remarkable persistence by establishing and maintaining multiple footholds within the victim company’s environment. One of the mechanisms utilized for persistence was a legacy F5 BIG-IP appliance, which was exposed to the internet and which the threat actor leveraged as an internal Command and Control (C&C). After one foothold was discovered and remediated, the threat actor swiftly pivoted to another, demonstrating agility and adaptability in evading detection. The threat actor exploited various entry points across the victim’s network infrastructure, indicating a comprehensive understanding of the target’s environment.

Also known as

Velvet Ant

Vulnerabilities exploited

Tooling and malware

PlugXImpacket

MITRE ATT&CK techniques

T1071 Application Layer ProtocolT1132 Data EncodingT1571 Non-Standard PortT1040 Network SniffingT1685 Disable or Modify ToolsT1686 Disable or Modify System FirewallT1049 System Network Connections DiscoveryT1083 File and Directory DiscoveryT1047 Windows Management InstrumentationT1570 Lateral Tool TransferT1133 External Remote ServicesT1055 Process InjectionT1211 Exploitation for Stealth

Coverage 3