Velvet Ant is a China-based advanced persistent threat group associated with intrusions involving telecommunications networks and enterprise network appliances. Its operations use compromised switches and internet-facing load balancers to maintain persistent access, conceal command-and-control communications, and pivot into internal networks. Its malware tooling includes PlugX, TinyShell, and the VelvetShell toolkit. In 2024, Velvet Ant exploited CVE-2024-20399 as a zero-day against Cisco Nexus switches running NX-OS. This command-injection vulnerability requires existing administrator-level access and enables execution with root privileges in the underlying Linux operating system, bypassing the NX-OS management layer. The group deployed custom malware on compromised switches to support remote command execution and file transfers. VelvetShell additionally provides network tunneling and proxying capabilities. Velvet Ant has also exploited vulnerabilities in internet-facing F5 load balancers to establish persistence and command-and-control channels. It used SSH tunnels through compromised F5 appliances to communicate with internal hosts infected with PlugX. On Windows systems, the group has used legitimate executables to load malicious DLLs through DLL search order hijacking and launch follow-on payloads, including PlugX. These techniques combine appliance-based access with malware execution on internal endpoints.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
CVE-2024-20399 allows an attacker to “jailbreak” devices, jumping from the NX-OS layer down to the Linux operating system. Cisco became aware of exploitation in the wild, reportedly in April 2024, and released an advisory and patches on July 1, 2024.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
3 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned for background on TinyShell adoption by other threat clusters, without attribution to the newly reported campaign.
Mentioned as a China-nexus cluster previously associated with TinyShell and targeting telecommunications networks and edge devices. The article does not connect Velvet Ant directly to the current activity.
Referenced as an ATT&CK-associated group for this detection technique; no activity by the group is described in the content.
Associated with the documented abuse pattern of using Windows finger.exe as a living-off-the-land binary for payload retrieval or covert command-and-control.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.