>samit_hota
Back to adversary profiles

Threat Actor Dossier

Velvet Ant (G1047): China-Nexus Espionage Group with Advanced Persistence

G1047

3 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
China-nexus
Motivation
Espionage · Data Theft
Samit Hota·
Target Sectors
Critical Infrastructure, Government, Telecommunications
Associated Malware
PlugX, VELVETSTING, VELVETTAP, VELVETSHELL, Impacket, GS-Netcat, Modified PAM/OpenSSH
#threat-actor#g1047

Overview

Velvet Ant, tracked by MITRE ATT&CK as G1047, is a highly sophisticated and persistent threat actor that has been active since at least 2021, with some forensic evidence suggesting operations dating back to 2016. Cybersecurity firm Sygnia, who publicly disclosed details about the group in June 2024, attributes Velvet Ant with high confidence to a China-nexus cyber espionage group. The group’s primary motivation is long-term access and data theft for espionage purposes, rather than disruption or financial gain. They are also believed to overlap with other known China-nexus clusters, such as UNC3886 (Mandiant) and CAULDRON PANDA (CrowdStrike), though this equivalence is assessed with moderate confidence.

Velvet Ant distinguishes itself through an impressive focus on infrastructure-layer persistence, often targeting devices that lack robust endpoint detection and response (EDR) coverage, such as network appliances and legacy systems. Their operations demonstrate a deep understanding of network architectures and a methodical approach to maintaining stealthy, prolonged access, sometimes for years at a time. This group consistently escalates its tactics when detected, pivoting to less-monitored infrastructure and rebuilding persistence from new vantage points.

Tactics & Techniques

Velvet Ant employs a diverse array of advanced tactics and techniques, heavily emphasizing stealth and complex persistence. Initial access often involves exploiting publicly exposed internet-facing remote services and vulnerabilities in network devices. The group has a history of leveraging zero-day exploits, as demonstrated by their exploitation of CVE-2024-20399, a command injection vulnerability in Cisco NX-OS software, to gain arbitrary command execution on Nexus switches. This particular exploit allowed them to escape the restrictive command-line interface (CLI) and access the underlying Linux operating system, deploying custom malware. Beyond Cisco, they have weaponized zero-days and n-days across various vendors, including Fortinet, VMware, and Juniper Junos OS.

Once inside, Velvet Ant focuses on establishing redundant and highly resilient persistence mechanisms. A defining characteristic of their tradecraft is the subversion of core Linux authentication and remote access components. They have been observed replacing legitimate PAM (Pluggable Authentication Modules) modules, specifically pam_unix.so, with backdoored versions. These malicious modules can accept hardcoded passwords for bypass, harvest credentials from legitimate login attempts, or both, enabling long-term access that can survive password resets. Similarly, they trojanize OpenSSH binaries (ssh, sshd, and scp) to capture credentials and command logs, further entrenching their control. The sheer effort involved, with nine distinct pam_unix.so variants identified, points to significant resources and deliberate development.

For lateral movement and command and control, Velvet Ant utilizes tools like the open-source Impacket toolkit for remote process execution (e.g., wmiexec.py) and file transfer. They establish reverse SSH tunnels for secure communication to victim devices and deploy custom SOCKS5 proxy scripts written in Perl to tunnel traffic covertly within compromised environments. The group is adept at living off the land and blending malicious activity with normal administrative operations, often by masquerading processes, injecting code into benign processes, and leveraging legitimate services. Defense evasion also includes disabling local security tools and EDR software, and modifying system firewall settings. They are known to prioritize edge devices and appliances because these assets typically lack robust EDR coverage and often have limited logging, making their activities harder to detect.

Notable Campaigns

Velvet Ant’s operations came into sharper public focus following Sygnia’s disclosures in 2024, detailing a multi-year intrusion campaign against a large organization, particularly in East Asia. One significant operation, dubbed “Operation Highland,” revealed the group’s ability to maintain access within a victim environment for nearly a decade, including sophisticated maneuvers into segregated critical infrastructure networks that lacked direct internet connectivity. During this campaign, the threat actor engineered a multi-stage access chain, pivoting from internet-facing systems to deep internal segments, demonstrating exceptional patience and operational security. Their ability to compromise the full authentication stack by backdooring PAM modules and OpenSSH binaries was a critical factor in their prolonged undetected presence.

Another notable aspect of their activity involved the exploitation of F5 BIG-IP load balancers. Velvet Ant has been observed abusing these appliances, especially those running outdated and vulnerable operating systems, using them as internal staging points and command-and-control (C2) relays to tunnel traffic out of victim networks. The discovery and exploitation of the Cisco NX-OS zero-day (CVE-2024-20399) in April 2024 further highlights their capabilities, allowing them to install custom backdoors directly on Cisco Nexus switches. While the specific victims of these campaigns are often unnamed, the targeting of network devices prevalent in enterprise and data center environments suggests a focus on high-value intelligence collection.

Moreover, if the moderate confidence attribution between Velvet Ant and UNC3886 holds, then UNC3886’s “Operation CYBER GUARDIAN,” which targeted four national telecommunications companies in Singapore over an 11-month period, could also be linked to this threat actor. This campaign involved the exploitation of various zero-days and n-days in Fortinet, VMware, and Juniper Junos OS devices, further underscoring the group’s capability in exploiting a wide range of network infrastructure.

Associated Malware & Tools

Velvet Ant employs a mix of publicly available tools, modified utilities, and custom-developed malware to achieve its objectives:

  • PlugX (Korplug): A versatile remote access trojan (RAT) frequently associated with Chinese APT activity, used for command-and-control and maintaining access on internal file servers.
  • VELVETSTING: A custom tool designed to parse encoded inbound commands on compromised F5 BIG-IP devices and execute them via the Unix shell.
  • VELVETTAP: Another custom tool, used to perform packet capture from compromised F5 BIG-IP appliances.
  • VELVETSHELL: A hybrid backdoor specifically deployed on Cisco Nexus switches after exploiting CVE-2024-20399. This malware provides extensive control, including arbitrary command execution, file transfer, and network tunneling.
  • Impacket: An open-source toolkit leveraged for lateral movement, including remote process execution via WMI (e.g., wmiexec.py) and file transfer over SMB.
  • Modified PAM Modules: Specifically, pam_unix.so, altered to enable authentication bypass and credential harvesting.
  • Modified OpenSSH Binaries: Trojanized ssh, sshd, and scp binaries used for credential theft, command logging, and maintaining persistent remote access.
  • Custom SOCKS5 Proxy: A Perl script serving as a SOCKS5 proxy server for covert network tunneling and lateral movement.
  • GS-Netcat: A modified version of this utility has been used to establish reverse shell connections to remote C2 servers.
  • ShadowPad: This modular backdoor has also been linked to Velvet Ant, further solidifying its China-nexus attribution.

Current Status

Velvet Ant remains an active and evolving threat actor, demonstrating a consistent operational tempo since at least 2021. Recent reporting throughout 2024 and 2025 details their continued exploitation of critical vulnerabilities, including the Cisco NX-OS zero-day, which was actively exploited in April 2024. The group’s resilience is evident in observations where, even after initial eradication efforts, they have resurfaced through dormant persistence mechanisms in unmonitored systems.

Their continued investment in discovering and weaponizing zero-day exploits, particularly against network infrastructure, suggests an ongoing capability and strategic focus on highly stealthy and persistent access. The sophisticated nature of their authentication bypass mechanisms, involving custom modifications to core Linux components, indicates sustained development and a high level of operational maturity. Security professionals should anticipate Velvet Ant to continue its focus on espionage, targeting critical infrastructure and high-value organizations by leveraging novel exploits and refining its complex, infrastructure-based persistence techniques.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call