# China-Linked Velvet Ant Group Hid in Linux Authentication System for Nearly a Decade


A sophisticated China-nexus hacking group managed to maintain hidden access to targeted networks for close to ten years by compromising the very foundation of Linux system security—the authentication layer itself. Security researchers at Sygnia have exposed the group's audacious strategy of backdooring PAM (Pluggable Authentication Modules) and OpenSSH, critical components that control who can log into systems, effectively giving attackers a master key that persists through standard remediation efforts.


The group, tracked by Sygnia as Velvet Ant, deliberately avoided the typical targets of defensive monitoring, instead embedding malicious code in authentication mechanisms where it could grant access to virtually any account without triggering conventional security alerts. This represents a particularly dangerous variant of supply-chain compromise and system-level persistence—one designed to survive the cleanup operations and security sweeps that would normally detect and remove backdoors.


## The Threat: Deep System Compromise


Velvet Ant's attack centered on modifying PAM and OpenSSH—components so fundamental to Linux systems that they handle the authentication logic for virtually every user login. Rather than creating obvious backdoors or injecting code into application layers, the group modified these authentication systems to accept hidden credentials alongside legitimate ones.


Key characteristics of the attack:


  • Persistence at the authentication layer: By backdooring PAM and OpenSSH, attackers ensured their access survived system reboots, password changes, and routine updates
  • Stealth through legitimacy: Authentication logs would record successful logins, but only if the backdoor credentials were used—making detection extremely difficult without forensic analysis
  • Scope of access: Compromise of authentication systems grants attackers effective control over any system using the backdoored libraries
  • Evasion of cleanup: Unlike malware in user directories or application binaries, authentication component modifications could survive standard incident response procedures

  • The group's choice of targets and dwell time suggests an intelligence gathering operation designed for long-term access rather than rapid exploitation. The nearly decade-long presence indicates either exceptional operational security or a significant gap in the target organization's security monitoring capabilities—likely both.


    ## Background and Context: A New Standard for Persistence


    This discovery reflects an evolution in advanced persistent threat (APT) tactics. Where previous generations of state-sponsored actors focused on rapid exploitation and data exfiltration, groups like Velvet Ant demonstrate a patient, infrastructure-focused approach centered on maintaining access indefinitely.


    Historical context:


    | Aspect | Typical APT | Velvet Ant Approach |

    |--------|-----------|-------------------|

    | Attack Surface | Applications, user accounts | Operating system authentication |

    | Persistence Method | Malware, cron jobs | Legitimate system component modification |

    | Detection Risk | High (external tools, artifacts) | Very low (internal OS component) |

    | Dwell Time | Months to 2-3 years | 10 years |

    | Cleanup Difficulty | Remove malware/scripts | Rebuild authentication systems |


    China-nexus groups have a documented history of sophisticated long-term operations, including the APT1 group (Comment Crew), APT10, and others. Velvet Ant appears to follow this pattern of patient, disciplined operations focused on intelligence collection rather than disruptive activity. The group's targeting and tactics suggest involvement in espionage rather than financial crime or destructive operations.


    ## Technical Details: How the Backdoor Worked


    Pluggable Authentication Modules (PAM) is a flexible authentication framework that allows Linux systems to support various authentication methods—passwords, fingerprints, two-factor authentication, and others. PAM modules are loaded at runtime and execute with high privileges, making them an attractive target for persistence.


    OpenSSH, the widely-deployed secure shell implementation, relies on PAM for user authentication on many Linux distributions. By compromising these components, attackers gained control over a critical authentication checkpoint.


    The attack likely involved:


    1. Initial compromise: Gaining root access through unpatched vulnerabilities or supply-chain compromise

    2. Modification of authentication libraries: Injecting code into PAM modules or OpenSSH binaries to recognize hidden credentials

    3. Credential hardcoding: Embedding specific usernames or passwords that would always authenticate successfully

    4. Log evasion: Potentially suppressing or modifying audit logs to hide successful backdoor authentication

    5. Legitimacy preservation: Ensuring that normal authentication still functioned to avoid suspicion


    The technical sophistication required to perform this compromise—maintaining compatibility with system updates, avoiding breaking legitimate authentication, and synchronizing across multiple systems—is substantial. This points to a well-resourced, organized threat actor with deep Linux expertise.


    ## Implications: Who Is at Risk and What Does It Mean


    Affected systems: Any organization running Linux systems that may have been supplied with compromised PAM or OpenSSH binaries, or that were directly targeted during the attack period.


    Immediate concerns:


  • Intelligence theft: A decade of access enabled comprehensive data collection, including intellectual property, communications, and operational security details
  • Lateral movement: Authentication system access provides a foundation for moving across entire networks
  • Supply chain exposure: If the compromised libraries were distributed through software repositories, third-party systems could also be affected
  • Incident response complications: Organizations that discovered the compromise may face significant challenges in determining the full scope of the breach

  • The discovery raises critical questions about how the compromise persisted undetected for so long and what triggers finally led to its discovery. Sygnia's findings suggest that standard defensive practices—antivirus scanning, malware detection, intrusion prevention—were insufficient to catch this threat.


    ## Recommendations for Organizations


    Immediate actions:


  • Audit PAM and OpenSSH integrity: Compare running versions against known-good binaries; use tools like aide (Advanced Intrusion Detection Environment) or ossec to monitor authentication component changes
  • Review authentication logs: Search for unusual successful authentications, especially those using unexpected usernames or source IPs
  • Assess dwell time: If the organization uses Linux systems, determine when current PAM and OpenSSH versions were deployed and whether they were sourced from trusted repositories
  • Rebuild critical systems: For organizations with sensitive data or high-value targets, consider rebuilding authentication systems from known-good media

  • Long-term defensive posture:


  • Implement host-based integrity monitoring: Use kernel-based intrusion detection to monitor runtime changes to critical system libraries
  • Enhance authentication logging: Enable comprehensive PAM logging and SSH verbose logging to capture authentication attempts
  • Supply chain verification: Validate that critical system components come from official sources; consider code-signing verification
  • Behavioral analysis: Monitor for authentication patterns that deviate from baselines, including successful logins to disabled accounts or from geographically impossible locations
  • Privileged access management: Implement PAM-based controls over system-level access to limit the damage from compromised credentials

  • ---


    ## HackWire Analysis


    This incident exemplifies a critical blind spot in enterprise security: the assumption that operating system components are inherently trustworthy. Most organizations invest heavily in endpoint detection and response (EDR) tools, network intrusion detection, and application-layer security. Few extend that same scrutiny to the authentication mechanisms that control access to everything else.


    The fact that Velvet Ant maintained access for nearly a decade without apparent detection speaks to a fundamental asymmetry in modern cybersecurity. Attackers can be patient; defenders must be right every single day. By choosing the authentication layer as a hiding place, the group exploited the reality that most security teams lack forensic visibility into kernel-level and system library changes in real time.


    What makes this particularly noteworthy is the *implicit trust* in Linux authentication systems. Unlike Windows systems, where authentication is more heavily scrutinized, Linux PAM modifications can be subtle and easily rationalized as legitimate configuration changes. Most organizations don't have automated comparison processes for PAM binary integrity across all systems.


    The broader pattern here matters: state-sponsored actors are increasingly moving toward infrastructure-level compromises—the kind that survive incident response, affect multiple organizations simultaneously, and provide persistent, resilient access. This is more valuable than any single data breach. A decade of access to authentication systems represents unparalleled intelligence collection capability.


    For defenders, this signals the need for a fundamental shift: treating operating system components with the same skepticism applied to third-party applications, implementing cryptographic verification of critical binaries, and deploying kernel-level monitoring as a baseline requirement rather than a luxury. — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Advanced Threats](https://www.hackwire.news/category/advanced-threats) coverage
  • Cross-reference with [Linux Security](https://www.hackwire.news/category/linux-security) and [Supply Chain Threats](https://www.hackwire.news/category/supply-chain)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)