Introduction
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits. Sygnia VelvetAnt 2024A Sygnia VelvetAnt 2024B
Activities and Tactics
Country of Origin: π¨π³ China
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1090.001 Internal Proxy
- T1574.001 DLL
- T1132 Data Encoding
- T1047 Windows Management Instrumentation
- T1059.004 Unix Shell
- T1571 Non-Standard Port
- T1133 External Remote Services
- T1570 Lateral Tool Transfer
- T1040 Network Sniffing
- T1083 File and Directory Discovery
- T1686 Disable or Modify System Firewall
- T1573.002 Asymmetric Cryptography
- T1569.002 Service Execution
- T1049 System Network Connections Discovery
- T1037.004 RC Scripts
- T1685 Disable or Modify Tools
- T1055 Process Injection
- T1071 Application Layer Protocol
- T1211 Exploitation for Stealth
- T1078.003 Local Accounts
- T1036.005 Match Legitimate Resource Name or Location
- T1021.002 SMB/Windows Admin Shares
ATT&CK technique IDs (denormalized)
- T1021.002
- T1036.005
- T1037.004
- T1040
- T1047
- T1049
- T1055
- T1059.004
- T1071
- T1078.003
- T1083
- T1090.001
- T1132
- T1133
- T1211
- T1569.002
- T1570
- T1571
- T1573.002
- T1574.001
- T1685
- T1686
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- CyberGate:
- Cyber Eye RAT:
- Xploit:
MITRE ATT&CK Software
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [2] Sygnia VelvetAnt 2024B Sygnia Team. (2024, July 1). China-Nexus Threat Group βVelvet Antβ Exploits Cisco Zero-Day (CVE-2024-20399) to Compromise Nexus Switch Devices β Advisory for Mitigation and Response. Retrieved March 14, 2025. [3] Sygnia VelvetAnt 2024A Sygnia Team. (2024, June 3). China-Nexus Threat Group βVelvet Antβ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.