Also known as: tracked as, a wingless wasp, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations
Velvet Ant is an advanced threat actor linked to Chinese state‑backed capabilities who has maintained undetected operations for more than a decade—with documented activity at least since 2021. Their repertoire centers on leveraging zero‑day vulnerabilities in network appliances (such as CVE-2023-46747 on F5 BIG‑IP TMUI and the recently disclosed CVE-2024-20399 in Cisco Nexus switches) to create backdoor administrator accounts or escape command line interfaces for arbitrary OS‑level execution. The group employs custom tools, notably VELVETSTING and VELVETTAP, that obfuscate inbound commands with encrypted payloads requiring a passkey before interpretation. They also utilize conventional utilities such as Impacket’s wmiexec.py for remote process injection via WMI and SMB shares, allowing lateral movement inside victim networks. A hallmark of their operations is persistent presence on compromised devices: they modify rc.local files or the system firewall using netsh.exe to open random high‑numbered ports. By hijacking DLL search order paths (e.g., deploying iviewers.dll masquerading as OLE/COM Object Viewer), they trigger execution of follow‑on payloads such as PlugX. Defensive strategies against Velvet Ant involve patching known device vulnerabilities, hardening remote access controls, monitoring for anomalous rc.local changes and high‑port listeners, detecting DLL injection events, and restricting the use of WMI/SMB-based toolkits.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Velvet Ant is a China‑aligned APT that has operated since at least 2021 and specializes in exploiting network devices such as F5 BIG‑IP load balancers and Cisco switches to gain long‑term covert access. The group is known for sophisticated persistence on these appliances, zero‑day exploitation, and the use of custom encrypted command tools to evade detection. They target a wide array of sectors—including government, defense, finance, healthcare, energy, and critical infrastructure—across dozens of countries, primarily for espionage objectives.
Goals & Targeting
Velvet Ant’s strategic objectives focus on state espionage: exfiltrating sensitive information from governments, defense contractors, and critical infrastructures to support policy and intelligence goals. The actor selects targets that store high‑value data or provide strategic insights—such as military networks or energy grid control systems—and operates across a broad geographical scope (CN, US, RU, IR, UA, etc.) to maximize intelligence reach. Their repeated emphasis on network device exploitation indicates a preference for gaining footholds that grant lateral mobility and deeper visibility into organizational traffic flows.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The group’s campaigns reveal a methodical, low‑profile approach: initial exploitation often begins via zero‑day or weak authentication on F5 BIG‑IP and Cisco devices, followed by installation of custom backdoors that enable encrypted remote command execution. Velvet Ant demonstrates persistence over extended periods—years in some cases—by maintaining elevated privileges through system modifications (firewall rules, rc.local persistence) and leveraging legitimate protocols for lateral movement. Their operations are sporadic but highly targeted: they focus on organizations where network device configuration data will yield valuable intel or provide a pivot to deeper enterprise environments. Notable past incidents include the large‑scale internal compromise of an unnamed international telecom operator via F5 exploitation in late 2023 and multiple attacks on US federal agencies through exploitative access to Cisco switches. Operational tempo is moderate: exploits are applied only when zero‑days or significant vulnerabilities present, reflecting a preference for high‑impact, low‑detection tactics rather than widespread opportunistic infections.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment relies heavily on two Sygnia Team advisories (June 2024 and July 2024) detailing the actor’s use of F5 and Cisco device exploits, custom tools such as VELVETSTING/VELVETTAP, and DLL hijacking techniques. Those sources provide credible evidence for core capabilities but lack independent corroboration across all reported sectors and geographic targets; many listed countries appear broad rather than specific attack claims. The MITRE ATT&CK list is largely inferred from linked technique associations, so individual tactic attribution may over‑generalize the actor’s behavior. Overall confidence is moderate: core device exploitation tactics are well supported, whereas details on broader campaign patterns and full toolchain usage remain partially speculative.
No campaigns linked yet.
No observed data linked yet.
34
Techniques
51
Tools
0
Campaigns
19
IOCs
0
Observed Data
9
Tactics