ATT&CKReferencesSygnia VelvetAnt 2024A

Sygnia VelvetAnt 2024A

Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
GroupVelvet Ant

Velvet Ant has transferred tools within victim environments using SMB.

T1036.005
Match Legitimate Resource Name or Location
GroupVelvet Ant

Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows.

T1037.004
RC Scripts
GroupVelvet Ant

Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence.

T1040
Network Sniffing
GroupVelvet Ant

Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.

T1047
Windows Management Instrumentation
ToolImpacket

Impacket's `wmiexec` module can be used to execute commands through WMI.

T1047
Windows Management Instrumentation
GroupVelvet Ant

Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI.

T1049
System Network Connections Discovery
GroupVelvet Ant

Velvet Ant has enumerated existing network connections on victim devices.

T1055
Process Injection
GroupVelvet Ant

Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them.

T1059.004
Unix Shell
GroupVelvet Ant

Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell.

T1071
Application Layer Protocol
GroupVelvet Ant

Velvet Ant has used reverse SSH tunnels to communicate to victim devices.

T1083
File and Directory Discovery
GroupVelvet Ant

Velvet Ant has enumerated local files and folders on victim devices.

T1090.001
Internal Proxy
GroupVelvet Ant

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

T1132
Data Encoding
GroupVelvet Ant

Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution.

T1133
External Remote Services
GroupVelvet Ant

Velvet Ant has leveraged access to internet-facing remote services to compromise and retain access to victim environments.

T1569.002
Service Execution
GroupVelvet Ant

Velvet Ant executed and installed PlugX as a Windows service.

T1570
Lateral Tool Transfer
GroupVelvet Ant

Velvet Ant transferred files laterally within victim networks through the Impacket toolkit.

T1570
Lateral Tool Transfer
ToolImpacket

Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks.

T1571
Non-Standard Port
GroupVelvet Ant

Velvet Ant has used random high number ports for PlugX listeners on victim devices.

T1571
Non-Standard Port
MalwarePlugX

PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities.

T1573.002
Asymmetric Cryptography
GroupVelvet Ant

Velvet Ant has used a reverse SSH shell to securely communicate with victim devices.

T1574.001
DLL
GroupVelvet Ant

Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX.

T1685
Disable or Modify Tools
GroupVelvet Ant

Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations.

T1686
Disable or Modify System Firewall
MalwarePlugX

PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity.

T1686
Disable or Modify System Firewall
GroupVelvet Ant

Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.