Login Software Became Velvet Ant’s Persistence Layer
The risk is in the login path itself. Once PAM or OpenSSH is altered, password resets and session kills can miss the real problem because the attacker owns the code that decides who gets in and what gets recorded.
Sygnia says Velvet Ant has been modifying Linux PAM and OpenSSH since 2016, with nine PAM variants found and altered OpenSSH binaries that could log credentials and commands. The affected environment was isolated from the internet, so the group used internet-facing systems as a bridge instead of relying on direct access.
The takeaway is broader than one campaign. Any bastion, remote-access host, or management plane that treats its authentication software as trusted can hide a long-lived credential theft mechanism inside the very control point defenders rely on.
Chinese hackers hijack auth flow, spy on isolated network for a decade
Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity.