A recent investigation revealed that one China-linked operation has remained undetected in victim networks for over three years. This stealthy campaign exploits outdated systems and network appliances, posing a major risk to critical infrastructure.
Security experts have identified new malware combining backdoor access with proxy evasion techniques. The group behind this operation uses zero-day vulnerabilities, including one targeting Cisco devices (CVE-2024-20399), to maintain persistence.
Our analysis dives into their evolving methods, defensive strategies, and real-world case studies. Understanding these risks helps professionals safeguard their networks against advanced intrusions.
Key Takeaways
- Advanced operations can hide in networks for years without detection.
- Legacy systems and network appliances are prime targets.
- New malware blends multiple evasion techniques.
- Zero-day exploits remain a critical threat.
- Proactive defense strategies are essential for protection.
Introduction to Velvet Ant: A Persistent Cyber Espionage Threat
Security researchers uncovered a long-running campaign targeting critical infrastructure with stealthy tactics. This threat actor operates with nation-state precision, focusing on intellectual property theft and supply chain mapping. Its ability to remain hidden for years underscores the need for proactive defenses.
Who Is Behind the Operations?
This advanced persistent threat (APT) leverages custom malware like PlugX and ShadowPad. Targets include manufacturers and enterprises with complex networks. Unlike smash-and-grab attacks, the focus is on persistent access to gather data silently.
Check Point’s research highlights exploitation of ORB devices, similar to Volt Typhoon’s tactics. Parallel intrusions suggest a shared contractor model, complicating attribution.
Geopolitical Ties and Strategic Goals
Evidence points to a China-nexus, aligning with broader cyber espionage patterns since 2008. The group avoids rapid data exfiltration, preferring long-term network control.
| Target Type | Vulnerabilities Exploited | Common Malware |
|---|---|---|
| Legacy Systems | Unpatched software, default credentials | PlugX variants |
| Network Appliances | Zero-days (e.g., Cisco CVE-2024-20399) | VELVETSHELL |
| Third-party Vendors | Weak supply chain security | ShadowPad |
Victims often lack robust logging, enabling the campaign to thrive. Internal proxy channels and external C&C servers ensure operational resilience.
Evolution of Attack Methods (2023–2025)
Recent analysis shows a strategic pivot from traditional endpoints to critical network appliances. This shift reflects broader trends in cyber operations, where attackers exploit trusted infrastructure to evade detection.

From Endpoints to Network Appliances
Early campaigns focused on Windows machines, but by 2024, F5 BIG-IP load balancers and Cisco Nexus switches became primary targets. These devices offer:
- Persistence: Built-in trust reduces suspicion.
- Limited monitoring: Few organizations inspect appliance traffic deeply.
- Lateral movement: Compromised appliances route malicious traffic internally.
For example, attackers used Impacket’s wmiexec.py to move through networks via WMI. By 2025, 73% of intrusions leveraged unpatched Cisco NX-OS vulnerabilities.
Legacy Systems Exploitation
Outdated systems like Windows Server 2003 remain vulnerable due to:
- Missing security patches
- Inadequate logging capabilities
- Default credentials left unchanged
On Linux devices, attackers modified rc.local to maintain access. Check Point’s research confirms similar patterns in ORB device targeting, where legacy systems act as stealthy command hubs.
Velvet Ant’s 2025 Campaign: Exploiting Cisco Switch Zero-Day (CVE-2024-20399)
A critical flaw in Cisco switches became the gateway for sophisticated cyber operations in 2025. The zero-day exploit, tracked as CVE-2024-20399, allowed attackers to escape the NX-OS CLI and gain root access to the underlying Linux layer. This pivot to network devices signaled a shift from traditional endpoint attacks.
Technical Breakdown of the Exploit
Cisco NX-OS operates in two layers: the application layer (CLI) and the Linux OS. Attackers abused valid admin credentials to inject commands, bypassing CLI restrictions. For example:
- Base64-encoded payloads hid malicious instructions like loading ufdm.so.
- The LD_PRELOAD technique hijacked execution to run disguised malware.
- Files like /root/ufdm masqueraded as legitimate processes.
This method aligned with MITRE ATT&CK T1574.006 (Dynamic Linker Hijacking). Forensic teams later reconstructed attacks using memory dumps, as files were deleted post-execution (T1070.004).
Deployment of VELVETSHELL Malware
The malware, dubbed VELVETSHELL, combined TinyShell’s backdoor functions with 3Proxy’s evasion tactics. Key steps included:
- Dropping the malicious library via Cisco’s curl binary.
- Renaming files to avoid detection (ufdm.so → libudev.so).
- Establishing command control through encrypted channels.
Sygnia’s analysis revealed Cisco zero-day exploitation left minimal traces, emphasizing the need for memory forensics. IoCs like /root/ufdm.so became critical for threat hunters.
Malware Arsenal: Tools and Custom Payloads
Modern cyber operations increasingly rely on hybrid malware to bypass traditional defenses. These custom payloads merge multiple attack functions, making detection and mitigation more challenging for security teams.

VELVETSHELL: A Hybrid of TinyShell and 3Proxy
The VELVETSHELL malware exemplifies this trend, combining TinyShell’s command execution with 3Proxy’s tunneling capabilities. This dual functionality allows attackers to:
- Execute remote commands via encrypted channels.
- Route traffic through compromised devices, evading network monitoring.
Forensic analysis revealed the malware’s use of LD_PRELOAD hijacking to load malicious libraries like ufdm.so, masquerading as legitimate processes.
PlugX and Other Legacy Malware Adaptations
While PlugX originated as a remote access trojan (RAT) in 2008, recent variants employ DLL sideloading via Windows SDK binaries. For example, attackers abuse iviewers.exe to load malicious DLLs, bypassing application whitelisting.
| Tool | Function | Evasion Technique |
|---|---|---|
| VELVETSHELL | Backdoor + tunneling | Dynamic linker hijacking |
| PlugX | Remote access | DLL search order hijacking |
| SAMRID | Lateral movement | Legacy system exploitation |
Other tools like SAMRID (a variant of EarthWorm) target F5 appliances, while VELVETTAP captures network traffic for reconnaissance. Attackers frequently use the passphrase 1qaz@WSXedc to encode commands, further obscuring their activities.
Detection requires monitoring for:
- Unusual process names (e.g., ufdm).
- Hourly C&C server polling.
- Anomalies in network appliance logs.
Stealth and Persistence: How Velvet Ant Evades Detection
Sophisticated cyber operations often rely on blending into trusted network traffic to avoid security tools. By abusing legitimate systems, attackers achieve long-term persistence while minimizing forensic evidence.

Leveraging Network Appliances as Hidden Hubs
F5 BIG-IP devices and Cisco switches became ideal command control channels. These appliances offer three key advantages:
- Trusted traffic: Blends malicious communications with normal operations
- Limited monitoring: Few organizations inspect appliance memory or processes
- Network positioning: Critical routing points enable lateral movement
One campaign used F5 devices to proxy traffic through port 443, mimicking HTTPS. This evasion technique bypassed firewall rules by appearing as encrypted web traffic.
Dynamic Linker Hijacking and Cleanup Tactics
Attackers frequently abuse the LD_PRELOAD environment variable to load malicious libraries. In observed cases:
- Malware like ufdm.so was loaded via linker hijacking
- Files were deleted post-execution (file deletion)
- Process names mimicked legitimate services (libudev.so)
This leaves minimal disk artifacts, forcing defenders to rely on memory forensics. One forensic team noted:
“We reconstructed attacks using volatility scans after finding empty /root/ufdm directory references.”
| Platform | Common Evasion Techniques | Detection Challenges |
|---|---|---|
| Windows | DLL sideloading, process hollowing | Legitimate process abuse |
| Linux | Linker hijacking, rc.local modification | Minimal default logging |
To detect these evasion techniques, we recommend:
- Baselining normal appliance memory usage
- Monitoring for Base64-encoded CLI commands
- Segmenting critical network devices
Case Studies: Velvet Ant’s Multi-Year Intrusions
Network defenders frequently encounter persistent threats hiding in overlooked systems. These case studies reveal how attackers maintain access for years while evading detection. We examine two critical scenarios that highlight evolving risks.
F5 BIG-IP Appliance Exploitation
One organization discovered a three-year breach originating from unpatched F5 BIG-IP systems. Attackers used:
- Disaster recovery interfaces with default credentials
- Reverse SSH tunnels to IP 202.61.136.158
- Firewall rules mimicking legitimate HTTPS traffic
The lateral movement phase involved SMB-based PlugX deployment on port 13742. Memory forensics later revealed credential harvesting through modified _bash_history_ files.
| Intrusion Phase | Techniques Used | Detection Indicators |
|---|---|---|
| Initial Access | F5 TMUI vulnerability (CVE-2022-1388) | Unusual mgmt interface logins |
| Persistence | _/config/cloud/startup_ script modification | Hourly C2 polling patterns |
| Exfiltration | DNS tunneling through BIG-IP DNS | Abnormal TXT record queries |
Legacy Server Proxy Chains
Windows Server 2008 systems became internal proxies in another case study. Attackers leveraged:
- Obsolete 3Proxy versions for traffic routing
- _rc.local_ modifications on Linux jump hosts
- Forged Kerberos tickets for Active Directory access
Traffic analysis showed reconnaissance commands hidden in ICMP packets. Wireshark filters like icmp.type==8 and icmp.code==0 helped identify malicious probes.
These legacy servers enabled attackers to bypass network segmentation. Post-remediation analysis revealed new entry points through VoIP systems, showing adaptive lateral movement tactics.
Defensive Strategies Against Velvet Ant’s Tactics
Protecting networks requires adapting to evolving attack methods. We outline practical steps to counter sophisticated intrusions targeting critical infrastructure.
Enhancing Logging and Threat Hunting
Effective threat hunting begins with comprehensive logging. Sygnia’s research shows attackers exploit gaps in security monitoring. Key recommendations include:
- Enable process-level auditing on all network devices
- Implement SIEM rules to detect Base64-encoded CLI commands
- Develop memory forensics capabilities for post-breach analysis
For network monitoring, we suggest analyzing internal traffic flows. Look for unusual patterns like hourly polling of external IPs. This helps identify potential command control channels.
| System Type | Critical Logs | Retention Period |
|---|---|---|
| Network Appliances | CLI command history | 180 days minimum |
| Legacy Servers | Authentication attempts | 90 days minimum |
Hardening Network Devices and Legacy Systems
System hardening reduces attack surfaces significantly. Follow these essential steps:
- Patch critical vulnerabilities within 24 hours of release
- Segment networks to limit lateral movement
- Restrict outbound traffic from critical systems
For Cisco Nexus switches:
- Disable unused management interfaces
- Enforce strict access control policies
- Audit configuration files monthly
Legacy Windows systems benefit from EDR deployment. Combine this with application whitelisting to prevent unauthorized code execution.
“Continuous monitoring of appliance OS processes provides early warning signs of compromise.” – Sygnia Incident Response Team
Implementing Zero Trust principles for network appliances adds another layer of protection. Verify every access request, regardless of origin.
Conclusion: Staying Ahead of Advanced Persistent Threats
The landscape of cyber defense demands constant vigilance. Recent campaigns highlight how adversaries evolve, shifting focus to network appliances and legacy systems. These advanced persistent threats exploit gaps in monitoring and outdated infrastructure.
To counter these risks, organizations must prioritize continuous monitoring and threat intelligence sharing. Network segmentation and strict access controls reduce attack surfaces. Supply chain assessments are equally critical, as third-party vulnerabilities often serve as entry points.
Strengthening your security posture requires a defense-in-depth approach. Combine logging enhancements with proactive threat hunting. Collaboration across industries helps identify emerging tactics early.
For deeper insights, review Sygnia’s advisory on mitigating these risks. Staying ahead means adapting faster than the threats evolve.