# Chinese Hackers Maintained 10-Year Grip on Critical Infrastructure Through Authentication Hijacking
Sygnia research reveals "Operation Highland," a sophisticated espionage campaign by the Velvet Ant threat group that bypassed air-gapped network protections through Nginx pivoting and PAM module manipulation.
Chinese state-sponsored hackers maintained persistent access to a critical infrastructure organization's isolated network for a decade, conducting full-scale cyber-espionage operations with undetected visibility into administrative activity. The intrusion, attributed to the Velvet Ant activity cluster and dubbed "Operation Highland" by Sygnia researchers, demonstrates how advanced threat actors can circumvent air-gap protections and sustain presence indefinitely through careful manipulation of authentication systems and network infrastructure.
The campaign began in 2016 with compromises of internet-facing systems, but its true sophistication emerged in how attackers pivoted to an "air-gapped" environment—networks designed to have no direct external connections. By targeting Linux authentication mechanisms at their core, Velvet Ant achieved a level of persistence that survived years without detection, raising serious questions about how organizations monitor their most critical systems.
## The Threat: A Decade of Undetected Access
The scope of this intrusion represents a catastrophic failure in defensive detection and network segmentation. For ten years, Velvet Ant operators had complete visibility into:
The threat group's persistence operated so cleanly that the organization remained unaware of the breach until Sygnia's researchers discovered the remnants of the operation. This suggests the attackers maintained such tight operational security that they avoided triggering any meaningful security alerts or anomalies over a decade-long presence.
Key Impact Areas:
## Background and Context: Velvet Ant's Track Record
The Velvet Ant activity cluster has earned recognition as one of the most sophisticated Chinese cyber-espionage operations in recent years:
| Year | Campaign | Target | Vector |
|------|----------|--------|--------|
| 2016-2026 | Operation Highland | Critical Infrastructure | Internet-facing systems → air-gapped pivot |
| 2021-2024 | F5 BIG-IP Campaign | Network infrastructure | Unpatched load balancers (3-year persistence) |
| 2024 | Cisco NX-OS Exploitation | Enterprise networks | Zero-day in Nexus switches |
Velvet Ant's modus operandi emphasizes patience, compartmentalization, and deep technical knowledge of operating system internals. Rather than pursuing smash-and-grab data theft, the group invests in long-term presence, credential harvesting, and intelligence collection—hallmarks of state-sponsored espionage operations targeting critical infrastructure.
## Technical Details: The Attack Chain
### Phase 1: Initial Compromise and Pivot Infrastructure
The attack began with the compromise of internet-facing servers. While the specific vulnerability or product isn't detailed in the research, Velvet Ant deployed a modified GS-Netcat reverse shell disguised as a legitimate system component. This shell connected to hardcoded relay domains and provided encrypted remote access—the attackers' initial beachhead.
To ensure persistence, Velvet Ant achieved it through one of two mechanisms:
### Phase 2: Internal Pivoting via SOCKS5 Proxy
With initial compromise established, attackers needed to reach deeper internal systems. They deployed a custom SOCKS5 proxy that:
smbd -D)This infrastructure allowed Velvet Ant to access systems not directly exposed to the internet while remaining invisible to standard network monitoring.
### Phase 3: Bridging the Air Gap—The Nginx Chain
The most sophisticated element involved breaching the air-gap through a series of compromised internet-facing services:
1. Compromised frontend Nginx intercepted specially crafted HTTP requests
2. Backend Nginx forwarded those requests to a FastCGI wrapper (fcgiwrap)
3. Custom binary named 'uptime' parsed HTTP POST parameters and established SSH connections to systems in the isolated network
4. SSH connections executed commands within the segregated environment
This chain meant that the isolated critical infrastructure network—supposedly protected by air-gap isolation—could be accessed through ordinary HTTP requests to internet-facing systems. The attackers never required a direct network path to the protected environment.
### Phase 4: Persistence Through Authentication Hijacking
Once inside the isolated network, Velvet Ant's strategy shifted to credential harvesting and long-term persistence. They targeted Linux Pluggable Authentication Modules (PAM)—the libraries that handle user authentication on Linux systems.
The Attack:
pam_unix.so modules with backdoored versionsParallel Credential Theft:
Velvet Ant also replaced critical OpenSSH components:
ssh clientsshd daemon scp utilityThe trojanized versions captured credentials, logged all commands entered during SSH sessions, and stored collected data locally for exfiltration. This dual-layer approach—both backdoors and active harvesting—ensured multiple pathways to regain access if one were discovered.
## Implications for Organizations
This operation has several critical implications:
### Network Segmentation Isn't Sufficient Alone
Air-gap protection failed because attackers compromised the systems *adjacent* to the isolated network. Organizations cannot rely solely on physical or logical isolation; they must harden the systems that serve as bridges to critical infrastructure.
### Authentication Systems Are High-Value Targets
By compromising PAM modules, attackers achieved the ultimate persistence mechanism. If an organization's authentication layer is compromised, defenders cannot trust *any* logs, cannot verify *any* user activity, and cannot safely reset credentials without complete system forensics first.
### Long Dwell Times Enable Deep Compromise
Ten years of undetected presence allowed comprehensive reconnaissance. Defenders must assume that sophisticated nation-state actors can establish presence and maintain it indefinitely if detection capabilities are insufficient.
### Operational Security Is a Double-Edged Sword
While Velvet Ant's meticulous operational security helped them avoid detection, it also slowed their potential for attack escalation. Organizations should recognize that sophisticated adversaries often prioritize persistence and intelligence gathering over rapid exploitation.
## Recommendations
For Critical Infrastructure Operators:
1. Harden Adjacent Systems: Apply the same security rigor to internet-facing systems that serve as bridges to isolated networks as you would to the isolated networks themselves.
2. Monitor Authentication Mechanisms: Implement integrity checking for PAM modules, OpenSSH binaries, and other authentication components. Use cryptographic verification and file integrity monitoring (FIM) to detect unauthorized modifications.
3. Segment Network Monitoring: Don't assume air-gapped networks are automatically invisible. Monitor Nginx configurations, FastCGI processes, and HTTP request patterns for anomalous behavior.
4. Credential Hygiene: Assume credentials may be compromised. Implement multi-factor authentication that doesn't rely solely on SSH key or password authentication. Use hardware security keys where feasible.
5. Forensic Preparation: Maintain offline, cryptographically verified system baselines. If authentication is compromised, you cannot trust any logs; you need pre-breach forensic baselines to detect changes.
6. Hunt for Persistence: Conduct active hunting for malicious PAM modules, modified OpenSSH binaries, unusual systemd services, and SOCKS5 proxies on isolated network boundaries. Velvet Ant's tooling, while sophisticated, still has detectable signatures.
---
## HackWire Analysis
This operation reveals a critical failure in how organizations conceptualize "air-gapping." Many defenders treat network isolation as a binary state—either a system is connected to the internet or it isn't—when in reality, modern infrastructure exists on a spectrum of connectivity. Velvet Ant's attack exploited a false assumption: that if a critical system has no *direct* internet connection, it's protected.
The truth is far more sobering. Any system adjacent to an isolated network becomes a potential bridge. A compromised Nginx server, a legitimate backend service, even a legitimate utility like FastCGI—when chained together, they become an indirect path into supposedly protected environments. This is not a new concept for defenders, but Operation Highland demonstrates that organizations are still failing to implement it in practice.
What's equally striking is the *patience* this operation required. Ten years of presence, with no apparent rush to exploitation. This pattern—infrastructure compromise, lateral movement, credential harvesting, intelligence collection—is the hallmark of state-sponsored espionage. The attackers weren't looking to steal credit cards or launch ransomware attacks. They were building a window into how a critical organization operates, who communicates with whom, and what their systems contain.
For defenders, the lesson is uncomfortable: sophisticated nation-state actors can achieve persistence indefinitely if they achieve a solid enough foothold. Detection, therefore, cannot rely on catching them *in the act* of exploitation. It must rely on finding them during the quiet phases—when they're installing persistence mechanisms, modifying authentication systems, or building internal pivots. This requires behavioral monitoring, baseline deviation detection, and frankly, more intelligent scrutiny of systems adjacent to critical infrastructure.
The fact that this remained undetected for a decade until external researchers found it should prompt serious questions at every organization with isolated critical systems: *Who's watching the watchers?* And *how would we actually know if someone was already inside?*
— HackWire Editorial
---
## Related Coverage