Threat group.View on attack.mitre.org
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
Velvet Ant has transferred tools within victim environments using SMB. |
| T1036.005 Match Legitimate Resource Name or Location |
Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows. |
| T1037.004 RC Scripts |
Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence. |
| T1040 Network Sniffing |
Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices. |
| T1047 Windows Management Instrumentation |
Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI. |
| T1049 System Network Connections Discovery |
Velvet Ant has enumerated existing network connections on victim devices. |
| T1055 Process Injection |
Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them. |
| T1059.004 Unix Shell |
Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell. |
| T1071 Application Layer Protocol |
Velvet Ant has used reverse SSH tunnels to communicate to victim devices. |
| T1078.003 Local Accounts |
Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges. |
| T1083 File and Directory Discovery |
Velvet Ant has enumerated local files and folders on victim devices. |
| T1090.001 Internal Proxy |
Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes. |
| T1132 Data Encoding |
Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution. |
| T1133 External Remote Services |
Velvet Ant has leveraged access to internet-facing remote services to compromise and retain access to victim environments. |
| T1211 Exploitation for Stealth |
Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.