Threats · 91 days ago
The risk is in the login path itself. Once PAM or OpenSSH is altered, password resets and session kills can miss the real problem because the attacker owns the code that decides who gets in and what gets recorded.
Sygnia says Velvet Ant has been modifying Linux PAM and OpenSSH since 2016, with nine PAM variants found and altered OpenSSH binaries that could log credentials and commands. The affected environment was isolated from the internet, so the group used internet-facing systems as a bridge instead of relying on direct access.
The takeaway is broader than one campaign. Any bastion, remote-access host, or management plane that treats its authentication software as trusted can hide a long-lived credential theft mechanism inside the very control point defenders rely on.
3 sources covering this story
China-linked spies backdoored authentication stack to stay hidden for years - Help Net Security
China-linked Velvet Ant APT spent a decade inside the target org's internal network, thanks to a backdoored authentication stack.
Chinese hackers hijack auth flow, spy on isolated network for a decade
Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity.
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Sygnia says Velvet Ant modified Linux PAM and OpenSSH components to steal credentials and maintain stealthy access since 2016.
Part of the PlainSec briefing for 2026-06-16