Velvet Ant
MITRE ATT&CK: G1047 View on attack.mitre.org
Aliases: Velvet Ant
- First seen
- 2021-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:30:31
Targeted industries: technology-and-telecommunications government-and-public-sector energy-and-utilities
Context
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.
Detection coverage
- 11 YARA rules
- 504 Sigma rules
Malware & tools used
- Internal Proxy (attack-pattern)
- DLL (attack-pattern)
- Data Encoding (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Unix Shell (attack-pattern)
- Non-Standard Port (attack-pattern)
- External Remote Services (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Network Sniffing (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Service Execution (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- RC Scripts (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Process Injection (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Exploitation for Stealth (attack-pattern)
- Local Accounts (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Impacket (malware)
- PlugX (malware)
Reports & references
- MITRE ATT&CK — G1047 (report)
- sygnia.co — China Nexus Threat Group Velvet Ant (report)
- sygnia.co — China Nexus Threat Group Velvet Ant Exploits Cisco 0 Day (report)
Attributed from
- Velvet Ant Cisco Network Switches Exploit Activity (CVE-2024-20399) (campaign)
- Velvet Ant F5 BIG-IP Espionage Activity (campaign)