news.mlab.sh
Back to the feed
apt

Chinese hackers hijack auth flow, spy on isolated network for a decade

Critical
Summary

Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers utilized a sophisticated attack chain involving modified shell tools, SOCKS5 proxies, and manipulated PAM modules to achieve full visibility into administrative activity and steal credentials. Remediation proved complex due to extensive component replacements, highlighting the importance of robust authentication protection.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.