FeedMalwareChinese hackers hijack auth flow, spy on isolated network fo...
MalwareBleeping Computer
9.0CRITICAL

Chinese hackers hijack auth flow, spy on isolated network for a decade

📅 13 June 2026 at 14:06 UTC📰 Bleeping ComputerView original source ↗
Chinese hackers hijack auth flow, spy on isolated network for a decade

Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Chinese hackers, attributed to the Velvet Ant cyberespionage threat group, hijacked an organization's authentication stack and maintained persistence for 10 years, gaining full visibility into administrative activity.

⚙️Technical Details
Affected Systems
F5 BIG-IP devicesNexus switches
Attack Vectors
Compromise of internet-facing serversDeployment of modified GS-Netcat reverse shellInstallation of custom SOCKS5 proxy for network traffic tunnelingModification of Nginx configuration to proxy requests to a backend server
💥Impact Assessment
Severity: critical
Who Is at Risk
Large organizations with isolated critical infrastructure networks and vulnerable internet-facing systems
🛡️Recommended Actions
1Treat authentication components such as PAM, OpenSSH, and Windows LSASS as critical security assets
2Implement EDR, file integrity monitoring, hardened privileged access, multi-factor authentication (MFA), and continuous monitoring for unauthorized modifications
3Plan for offline recovery with strict backups and adequate scheduling
📦Affected Products
F5 BIG-IP devicesNexus switches

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed