Velvet Ant

MITRE ATT&CK: G1047 View on attack.mitre.org

Aliases: Velvet Ant

First seen
2021-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:30:31

Targeted industries: technology-and-telecommunications government-and-public-sector energy-and-utilities

Context

Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.

Detection coverage

  • 11 YARA rules
  • 504 Sigma rules

Malware & tools used

  • Internal Proxy (attack-pattern)
  • DLL (attack-pattern)
  • Data Encoding (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Unix Shell (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • External Remote Services (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Network Sniffing (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Service Execution (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • RC Scripts (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Process Injection (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Exploitation for Stealth (attack-pattern)
  • Local Accounts (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Impacket (malware)
  • PlugX (malware)

Reports & references

  • MITRE ATT&CK — G1047 (report)
  • sygnia.co — China Nexus Threat Group Velvet Ant (report)
  • sygnia.co — China Nexus Threat Group Velvet Ant Exploits Cisco 0 Day (report)

Attributed from

  • Velvet Ant Cisco Network Switches Exploit Activity (CVE-2024-20399) (campaign)
  • Velvet Ant F5 BIG-IP Espionage Activity (campaign)

External references