Login Software Became Velvet Ant’s Persistence Layer
The risk is in the login path itself. Once PAM or OpenSSH is altered, password resets and session kills can miss the real problem because the attacker owns the code that decides who gets in and what gets recorded.
Sygnia says Velvet Ant has been modifying Linux PAM and OpenSSH since 2016, with nine PAM variants found and altered OpenSSH binaries that could log credentials and commands. The affected environment was isolated from the internet, so the group used internet-facing systems as a bridge instead of relying on direct access.
The takeaway is broader than one campaign. Any bastion, remote-access host, or management plane that treats its authentication software as trusted can hide a long-lived credential theft mechanism inside the very control point defenders rely on.