apt
Chinese hackers hijack auth flow, spy on isolated network for a decade
Critical
Summary
Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers utilized a sophisticated attack chain involving modified shell tools, SOCKS5 proxies, and manipulated PAM modules to achieve full visibility into administrative activity and steal credentials. Remediation proved complex due to extensive component replacements, highlighting the importance of robust authentication protection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data