China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
A China-linked threat actor, identified as Velvet Ant, has been discovered backdooring Linux login software for nearly a decade, gaining persistent access to a network with no direct internet connectivity. The group’s tactic involved modifying core system components like PAM and OpenSSH to silently record user credentials and commands. This highlights the importance of securing critical infrastructure components that are often overlooked in security monitoring.
The Velvet Ant group, operating from China, infiltrated the target network by exploiting the inherent trust placed in Linux login systems. Instead of deploying traditional malware, they subtly altered the PAM and OpenSSH components, effectively creating a persistent backdoor. This allowed them to monitor user activity, including usernames, passwords, and commands executed, without triggering typical security alerts. The attackers utilized a staged approach, leveraging internet-facing systems as a bridge to reach the isolated network segment, further complicating detection efforts.
