Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Velvet Ant

Also known as: tracked as, a wingless wasp, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

Velvet Ant is an advanced threat actor linked to Chinese state‑backed capabilities who has maintained undetected operations for more than a decade—with documented activity at least since 2021. Their repertoire centers on leveraging zero‑day vulnerabilities in network appliances (such as CVE-2023-46747 on F5 BIG‑IP TMUI and the recently disclosed CVE-2024-20399 in Cisco Nexus switches) to create backdoor administrator accounts or escape command line interfaces for arbitrary OS‑level execution. The group employs custom tools, notably VELVETSTING and VELVETTAP, that obfuscate inbound commands with encrypted payloads requiring a passkey before interpretation. They also utilize conventional utilities such as Impacket’s wmiexec.py for remote process injection via WMI and SMB shares, allowing lateral movement inside victim networks. A hallmark of their operations is persistent presence on compromised devices: they modify rc.local files or the system firewall using netsh.exe to open random high‑numbered ports. By hijacking DLL search order paths (e.g., deploying iviewers.dll masquerading as OLE/COM Object Viewer), they trigger execution of follow‑on payloads such as PlugX. Defensive strategies against Velvet Ant involve patching known device vulnerabilities, hardening remote access controls, monitoring for anomalous rc.local changes and high‑port listeners, detecting DLL injection events, and restricting the use of WMI/SMB-based toolkits.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Healthcare
Education
Manufacturing
Critical infrastructure
Non profit
Energy
Media
Pharmaceutical
Aviation
Hospitality
Information technology
Aerospace
Retail
Chemical
Think tank
Transportation
Mining
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

CN
US
RU
IR
UA
VN
JP
IL
GB
AU
SA
PK
TW
AE
SG
KR
IN
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 4 days ago

Executive Summary

Velvet Ant is a China‑aligned APT that has operated since at least 2021 and specializes in exploiting network devices such as F5 BIG‑IP load balancers and Cisco switches to gain long‑term covert access. The group is known for sophisticated persistence on these appliances, zero‑day exploitation, and the use of custom encrypted command tools to evade detection. They target a wide array of sectors—including government, defense, finance, healthcare, energy, and critical infrastructure—across dozens of countries, primarily for espionage objectives.

Goals & Targeting

Velvet Ant’s strategic objectives focus on state espionage: exfiltrating sensitive information from governments, defense contractors, and critical infrastructures to support policy and intelligence goals. The actor selects targets that store high‑value data or provide strategic insights—such as military networks or energy grid control systems—and operates across a broad geographical scope (CN, US, RU, IR, UA, etc.) to maximize intelligence reach. Their repeated emphasis on network device exploitation indicates a preference for gaining footholds that grant lateral mobility and deeper visibility into organizational traffic flows.

Enhanced Description

Key Capabilities

  • Advanced persistence mechanisms on F5 BIG‑IP devices via modified /etc/rc.local and random high‑numbered firewall ports
  • Zero‑day exploitation of Cisco switches (CVE-2024-20399) and F5 TMUI (CVE-2023-46747) to gain OS‑level access
  • Custom encrypted command framework VELVETSTING for stealthy control traffic
  • Use of VELVETTAP for packet capture on compromised devices
  • DLL search order hijacking with malicious iviewers.dll to launch PlugX payloads
  • Lateral movement with Impacket toolkit and wmiexec.py over WMI, SMB shares, and reverse SSH tunnels
  • Active disabling or evasion of local security tools/endpoint detection and response (EDR) software
  • Defense evasion via manipulation of system firewall settings and service execution (T1569/T1548)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control

ATT&CK Techniques

T1047
T1037
T1133
T1036.005
T1574.001
T1040
T1071
T1036
T1055
T1021.002
T1021
T1548
T1090
T1059
T1083
T1049
T1098
T1059.004
T1574
T1078
T1571
T1573
T1685
T1573.002
T1570
T1132
T1569
T1037.004
T1134
T1686
T1569.002
T1090.001
T1078.003
T1211

Software / Tooling

VELVETSTING
VELVETTAP
PlugX
Impacket
wmiexec.py
Machete
Akira
Octopus
AppleJeus
Turla
Winnti
Cobalt Strike
DarkHotel
Medusa
Nexus
SideWinder
Poseidon
Predator
OilRig
Guard
Venomous
APT38
Moonstone Sleet
Hafnium
Stinger
MuddyWater
Custom RAT

Campaigns & Victims

The group’s campaigns reveal a methodical, low‑profile approach: initial exploitation often begins via zero‑day or weak authentication on F5 BIG‑IP and Cisco devices, followed by installation of custom backdoors that enable encrypted remote command execution. Velvet Ant demonstrates persistence over extended periods—years in some cases—by maintaining elevated privileges through system modifications (firewall rules, rc.local persistence) and leveraging legitimate protocols for lateral movement. Their operations are sporadic but highly targeted: they focus on organizations where network device configuration data will yield valuable intel or provide a pivot to deeper enterprise environments. Notable past incidents include the large‑scale internal compromise of an unnamed international telecom operator via F5 exploitation in late 2023 and multiple attacks on US federal agencies through exploitative access to Cisco switches. Operational tempo is moderate: exploits are applied only when zero‑days or significant vulnerabilities present, reflecting a preference for high‑impact, low‑detection tactics rather than widespread opportunistic infections.

IOC Patterns

  • Spear‑phishing with macro-laced Office documents
  • Credential dumping via PluggX and Impacket tools
  • Use of reverse SSH tunnels for command and control traffic
  • Exploitation of zero-days in F5 BIG‑IP TMUI (CVE-2023-46747)
  • Vulnerability exploitation on Cisco Nexus switches (CVE-2024-20399)

Recommended Actions

  • Patch all F5 BIG‑IP devices against CVE-2023-46747 and disable legacy authentication methods; prioritize devices with access to corporate networks.
  • Apply security patches for Cisco switch firmware addressing CVE-2024-20399 as soon as available, or consider disabling exposed CLI interfaces if patching is delayed.
  • Enforce least privilege on network device accounts; disable unused admin users and enforce MFA for privileged remote management.
  • Deploy EDR/EDR‑like visibility into process creation events to detect DLL injection and high‑port listeners originating from internal hosts.
  • Audit rc.local and system service modifications across all network appliances; block unauthorized edits to persistence scripts.
  • Restrict use of WMI, SMB, and SSH for remote administration by limiting the IP ranges allowed and logging all traffic.
  • Segment management networks: keep device configuration planes separate from data planes and corporate LAN, using out‑of‑band access when feasible.
  • Implement application firewall rules to block non‑essential outbound connections on high random ports used by PlugX or other custom tools.
  • Deploy threat hunting queries that flag base64‑encoded commands and obfuscated shell scripts characteristic of VELVETSTING.
  • Educate staff about spear‑phishing techniques that deliver macro-laden Office documents as a vector for initial compromise.

Suggested Tags

APT
espionage
network-device targeting
zero-day exploitation
state-sponsored
China-based
F5 BIG-IP
Cisco Switch
PlugX
Impacket

Confidence Assessment

The assessment relies heavily on two Sygnia Team advisories (June 2024 and July 2024) detailing the actor’s use of F5 and Cisco device exploits, custom tools such as VELVETSTING/VELVETTAP, and DLL hijacking techniques. Those sources provide credible evidence for core capabilities but lack independent corroboration across all reported sectors and geographic targets; many listed countries appear broad rather than specific attack claims. The MITRE ATT&CK list is largely inferred from linked technique associations, so individual tactic attribution may over‑generalize the actor’s behavior. Overall confidence is moderate: core device exploitation tactics are well supported, whereas details on broader campaign patterns and full toolchain usage remain partially speculative.

ATT&CK Techniques

Command & Control
7 techniques
Privilege Escalation
1 technique
Stealth
9 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Sygnia VelvetAnt 2024B — Sygnia Team. (2024, July 1). China-Nexus Threat Group ‘Velvet Ant’ Exploits Cisco Zero-Day (CVE-2024-20399) to Compromise Nexus Switch Devices – Advisory for Mitigation and Response. Retrieved March 14, 2025.
  2. Sygnia VelvetAnt 2024A — Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.
  3. attack.mitre.org — Cited by web research for: Sandworm Team
  4. attack.mitre.org — Cited by web research for: T1071
  5. pmc.ncbi.nlm.nih.gov — Cited by web research for: Predator
  6. unit42.paloaltonetworks.com — Cited by web research for: Unknown
  7. pmc.ncbi.nlm.nih.gov — Cited by web research for: analyses.All
  8. https://www.sygnia.com/2024/06/china-nexus-threat-group-velvet-ant-abuses-f5-load-balancers-for-persistence — Cited by AI analysis.
  9. https://www.sygnia.com/2024/07/china-nexus-threat-group-velvet-ant-exploits-cisco-zero-day-cve-2024-20399 — Cited by AI analysis.

Intel Summary

34

Techniques

51

Tools

0

Campaigns

19

IOCs

0

Observed Data

9

Tactics

Tags

Zero-Day Exploitation
APT
Network Infrastructure
Zero-Day Exploits
Persistence
espionage
network-device targeting
zero-day exploitation
state-sponsored
China-based
F5 BIG-IP
Cisco Switch
PlugX
Impacket

Details

MITRE ID
G1047
Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--e1fc262c-dad2-4b82-abda-5f08dd134971
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.