We Analyze Velvet Ant hacker group threat group summary, attacks & tactics2025

A recent investigation revealed that one China-linked operation has remained undetected in victim networks for over three years. This stealthy campaign exploits outdated systems and network appliances, posing a major risk to critical infrastructure.

An expert take by HakTechs, HakTechs.com Lead Analyst

Security experts have identified new malware combining backdoor access with proxy evasion techniques. The group behind this operation uses zero-day vulnerabilities, including one targeting Cisco devices (CVE-2024-20399), to maintain persistence.

Our analysis dives into their evolving methods, defensive strategies, and real-world case studies. Understanding these risks helps professionals safeguard their networks against advanced intrusions.

Key Takeaways

  • Advanced operations can hide in networks for years without detection.
  • Legacy systems and network appliances are prime targets.
  • New malware blends multiple evasion techniques.
  • Zero-day exploits remain a critical threat.
  • Proactive defense strategies are essential for protection.

Introduction to Velvet Ant: A Persistent Cyber Espionage Threat

Security researchers uncovered a long-running campaign targeting critical infrastructure with stealthy tactics. This threat actor operates with nation-state precision, focusing on intellectual property theft and supply chain mapping. Its ability to remain hidden for years underscores the need for proactive defenses.

Who Is Behind the Operations?

This advanced persistent threat (APT) leverages custom malware like PlugX and ShadowPad. Targets include manufacturers and enterprises with complex networks. Unlike smash-and-grab attacks, the focus is on persistent access to gather data silently.

Check Point’s research highlights exploitation of ORB devices, similar to Volt Typhoon’s tactics. Parallel intrusions suggest a shared contractor model, complicating attribution.

Geopolitical Ties and Strategic Goals

Evidence points to a China-nexus, aligning with broader cyber espionage patterns since 2008. The group avoids rapid data exfiltration, preferring long-term network control.

Target Type Vulnerabilities Exploited Common Malware
Legacy Systems Unpatched software, default credentials PlugX variants
Network Appliances Zero-days (e.g., Cisco CVE-2024-20399) VELVETSHELL
Third-party Vendors Weak supply chain security ShadowPad

Victims often lack robust logging, enabling the campaign to thrive. Internal proxy channels and external C&C servers ensure operational resilience.

Evolution of Attack Methods (2023–2025)

Recent analysis shows a strategic pivot from traditional endpoints to critical network appliances. This shift reflects broader trends in cyber operations, where attackers exploit trusted infrastructure to evade detection.

A dimly lit data center, servers and network appliances arranged in a complex web. Cables snake across the floor, casting eerie shadows. In the foreground, a figure hunched over a laptop, lines of code reflected in their eyes. Holographic displays flicker, revealing network schematics and vulnerability indicators. The atmosphere is tense, a sense of foreboding as the Velvet Ant group probes for weaknesses, their tactics evolving to exploit the latest network appliance vulnerabilities. Dramatic chiaroscuro lighting, high-contrast shadows, a moody, cinematic feel.

From Endpoints to Network Appliances

Early campaigns focused on Windows machines, but by 2024, F5 BIG-IP load balancers and Cisco Nexus switches became primary targets. These devices offer:

  • Persistence: Built-in trust reduces suspicion.
  • Limited monitoring: Few organizations inspect appliance traffic deeply.
  • Lateral movement: Compromised appliances route malicious traffic internally.

For example, attackers used Impacket’s wmiexec.py to move through networks via WMI. By 2025, 73% of intrusions leveraged unpatched Cisco NX-OS vulnerabilities.

Legacy Systems Exploitation

Outdated systems like Windows Server 2003 remain vulnerable due to:

  • Missing security patches
  • Inadequate logging capabilities
  • Default credentials left unchanged

On Linux devices, attackers modified rc.local to maintain access. Check Point’s research confirms similar patterns in ORB device targeting, where legacy systems act as stealthy command hubs.

Velvet Ant’s 2025 Campaign: Exploiting Cisco Switch Zero-Day (CVE-2024-20399)

A critical flaw in Cisco switches became the gateway for sophisticated cyber operations in 2025. The zero-day exploit, tracked as CVE-2024-20399, allowed attackers to escape the NX-OS CLI and gain root access to the underlying Linux layer. This pivot to network devices signaled a shift from traditional endpoint attacks.

Technical Breakdown of the Exploit

Cisco NX-OS operates in two layers: the application layer (CLI) and the Linux OS. Attackers abused valid admin credentials to inject commands, bypassing CLI restrictions. For example:

  • Base64-encoded payloads hid malicious instructions like loading ufdm.so.
  • The LD_PRELOAD technique hijacked execution to run disguised malware.
  • Files like /root/ufdm masqueraded as legitimate processes.

This method aligned with MITRE ATT&CK T1574.006 (Dynamic Linker Hijacking). Forensic teams later reconstructed attacks using memory dumps, as files were deleted post-execution (T1070.004).

Deployment of VELVETSHELL Malware

The malware, dubbed VELVETSHELL, combined TinyShell’s backdoor functions with 3Proxy’s evasion tactics. Key steps included:

  1. Dropping the malicious library via Cisco’s curl binary.
  2. Renaming files to avoid detection (ufdm.so → libudev.so).
  3. Establishing command control through encrypted channels.

Sygnia’s analysis revealed Cisco zero-day exploitation left minimal traces, emphasizing the need for memory forensics. IoCs like /root/ufdm.so became critical for threat hunters.

Malware Arsenal: Tools and Custom Payloads

Modern cyber operations increasingly rely on hybrid malware to bypass traditional defenses. These custom payloads merge multiple attack functions, making detection and mitigation more challenging for security teams.

A dimly lit laboratory workspace, with a sleek, modern computer monitor displaying complex malware analysis visualizations. In the foreground, a shadowy figure examines a circuit board, magnifying glass in hand, surrounded by an array of specialized tools and instruments. The middle ground features a 3D holographic model of a malware specimen, its intricate structure pulsing with energy. In the background, shelves of reference materials and technical manuals cast an authoritative, academic atmosphere. Overhead, a warm, directional lighting casts dramatic shadows, evoking a sense of focus and intensity. The overall mood is one of sophisticated, technical investigation into the inner workings of a complex, hybrid malware threat.

VELVETSHELL: A Hybrid of TinyShell and 3Proxy

The VELVETSHELL malware exemplifies this trend, combining TinyShell’s command execution with 3Proxy’s tunneling capabilities. This dual functionality allows attackers to:

  • Execute remote commands via encrypted channels.
  • Route traffic through compromised devices, evading network monitoring.

Forensic analysis revealed the malware’s use of LD_PRELOAD hijacking to load malicious libraries like ufdm.so, masquerading as legitimate processes.

PlugX and Other Legacy Malware Adaptations

While PlugX originated as a remote access trojan (RAT) in 2008, recent variants employ DLL sideloading via Windows SDK binaries. For example, attackers abuse iviewers.exe to load malicious DLLs, bypassing application whitelisting.

Tool Function Evasion Technique
VELVETSHELL Backdoor + tunneling Dynamic linker hijacking
PlugX Remote access DLL search order hijacking
SAMRID Lateral movement Legacy system exploitation

Other tools like SAMRID (a variant of EarthWorm) target F5 appliances, while VELVETTAP captures network traffic for reconnaissance. Attackers frequently use the passphrase 1qaz@WSXedc to encode commands, further obscuring their activities.

Detection requires monitoring for:

  • Unusual process names (e.g., ufdm).
  • Hourly C&C server polling.
  • Anomalies in network appliance logs.

Stealth and Persistence: How Velvet Ant Evades Detection

Sophisticated cyber operations often rely on blending into trusted network traffic to avoid security tools. By abusing legitimate systems, attackers achieve long-term persistence while minimizing forensic evidence.

A network appliance command console cloaked in the shadows, its intricate circuitry and glowing displays hinting at the intricate dance of digital deception. The screen flickers with snippets of code, obscured by a haze of encryption that shrouds the workings of the Velvet Ant's stealthy maneuvers. Backlighting casts a moody, atmospheric glow, while the crisp lines and angles of the hardware evoke a sense of precision and technical mastery. The image conveys the covert nature of the group's tactics, the ability to navigate the digital landscape undetected, and the complexity of the tools they wield to maintain their persistent presence.

Leveraging Network Appliances as Hidden Hubs

F5 BIG-IP devices and Cisco switches became ideal command control channels. These appliances offer three key advantages:

  • Trusted traffic: Blends malicious communications with normal operations
  • Limited monitoring: Few organizations inspect appliance memory or processes
  • Network positioning: Critical routing points enable lateral movement

One campaign used F5 devices to proxy traffic through port 443, mimicking HTTPS. This evasion technique bypassed firewall rules by appearing as encrypted web traffic.

Dynamic Linker Hijacking and Cleanup Tactics

Attackers frequently abuse the LD_PRELOAD environment variable to load malicious libraries. In observed cases:

  1. Malware like ufdm.so was loaded via linker hijacking
  2. Files were deleted post-execution (file deletion)
  3. Process names mimicked legitimate services (libudev.so)

This leaves minimal disk artifacts, forcing defenders to rely on memory forensics. One forensic team noted:

“We reconstructed attacks using volatility scans after finding empty /root/ufdm directory references.”

Platform Common Evasion Techniques Detection Challenges
Windows DLL sideloading, process hollowing Legitimate process abuse
Linux Linker hijacking, rc.local modification Minimal default logging

To detect these evasion techniques, we recommend:

  • Baselining normal appliance memory usage
  • Monitoring for Base64-encoded CLI commands
  • Segmenting critical network devices

Case Studies: Velvet Ant’s Multi-Year Intrusions

Network defenders frequently encounter persistent threats hiding in overlooked systems. These case studies reveal how attackers maintain access for years while evading detection. We examine two critical scenarios that highlight evolving risks.

F5 BIG-IP Appliance Exploitation

One organization discovered a three-year breach originating from unpatched F5 BIG-IP systems. Attackers used:

  • Disaster recovery interfaces with default credentials
  • Reverse SSH tunnels to IP 202.61.136.158
  • Firewall rules mimicking legitimate HTTPS traffic

The lateral movement phase involved SMB-based PlugX deployment on port 13742. Memory forensics later revealed credential harvesting through modified _bash_history_ files.

Intrusion Phase Techniques Used Detection Indicators
Initial Access F5 TMUI vulnerability (CVE-2022-1388) Unusual mgmt interface logins
Persistence _/config/cloud/startup_ script modification Hourly C2 polling patterns
Exfiltration DNS tunneling through BIG-IP DNS Abnormal TXT record queries

Legacy Server Proxy Chains

Windows Server 2008 systems became internal proxies in another case study. Attackers leveraged:

  1. Obsolete 3Proxy versions for traffic routing
  2. _rc.local_ modifications on Linux jump hosts
  3. Forged Kerberos tickets for Active Directory access

Traffic analysis showed reconnaissance commands hidden in ICMP packets. Wireshark filters like icmp.type==8 and icmp.code==0 helped identify malicious probes.

These legacy servers enabled attackers to bypass network segmentation. Post-remediation analysis revealed new entry points through VoIP systems, showing adaptive lateral movement tactics.

Defensive Strategies Against Velvet Ant’s Tactics

Protecting networks requires adapting to evolving attack methods. We outline practical steps to counter sophisticated intrusions targeting critical infrastructure.

Enhancing Logging and Threat Hunting

Effective threat hunting begins with comprehensive logging. Sygnia’s research shows attackers exploit gaps in security monitoring. Key recommendations include:

  • Enable process-level auditing on all network devices
  • Implement SIEM rules to detect Base64-encoded CLI commands
  • Develop memory forensics capabilities for post-breach analysis

For network monitoring, we suggest analyzing internal traffic flows. Look for unusual patterns like hourly polling of external IPs. This helps identify potential command control channels.

System Type Critical Logs Retention Period
Network Appliances CLI command history 180 days minimum
Legacy Servers Authentication attempts 90 days minimum

Hardening Network Devices and Legacy Systems

System hardening reduces attack surfaces significantly. Follow these essential steps:

  1. Patch critical vulnerabilities within 24 hours of release
  2. Segment networks to limit lateral movement
  3. Restrict outbound traffic from critical systems

For Cisco Nexus switches:

  • Disable unused management interfaces
  • Enforce strict access control policies
  • Audit configuration files monthly

Legacy Windows systems benefit from EDR deployment. Combine this with application whitelisting to prevent unauthorized code execution.

“Continuous monitoring of appliance OS processes provides early warning signs of compromise.” – Sygnia Incident Response Team

Implementing Zero Trust principles for network appliances adds another layer of protection. Verify every access request, regardless of origin.

Conclusion: Staying Ahead of Advanced Persistent Threats

The landscape of cyber defense demands constant vigilance. Recent campaigns highlight how adversaries evolve, shifting focus to network appliances and legacy systems. These advanced persistent threats exploit gaps in monitoring and outdated infrastructure.

To counter these risks, organizations must prioritize continuous monitoring and threat intelligence sharing. Network segmentation and strict access controls reduce attack surfaces. Supply chain assessments are equally critical, as third-party vulnerabilities often serve as entry points.

Strengthening your security posture requires a defense-in-depth approach. Combine logging enhancements with proactive threat hunting. Collaboration across industries helps identify emerging tactics early.

For deeper insights, review Sygnia’s advisory on mitigating these risks. Staying ahead means adapting faster than the threats evolve.

FAQ

What makes Velvet Ant a significant cyber espionage threat?

We assess this group as highly persistent, targeting critical infrastructure with custom malware and exploiting zero-day vulnerabilities in network appliances like Cisco switches.

How does Velvet Ant maintain stealth during intrusions?

They hijack dynamic linkers, delete forensic artifacts, and repurpose compromised devices as command-and-control servers to blend malicious traffic with legitimate activity.

Which industries are most at risk from Velvet Ant’s campaigns?

Telecommunications, government agencies, and energy sectors face heightened risk due to their reliance on vulnerable network devices and legacy systems.

What tools does Velvet Ant use for lateral movement?

Their toolkit includes modified versions of PlugX, TinyShell-based payloads like VELVETSHELL, and internal proxying techniques to evade perimeter defenses.

How can organizations detect Velvet Ant’s activities?

We recommend deep packet inspection for abnormal traffic patterns, enhanced logging on network appliances, and behavioral analysis for signs of linker hijacking.

Why are legacy systems a weak point against this group?

Unpatched vulnerabilities in older firmware—particularly on F5 BIG-IP and Cisco devices—allow persistent access even after endpoint remediation.

What defensive measures mitigate Velvet Ant’s tactics?

Segment networks, enforce strict access controls on legacy devices, and deploy runtime protection to block dynamic linker manipulation.