Velvet Ant
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.
Velvet Ant is a persistent threat actor active since 2021, targeting network devices and appliances with zero-day exploits.
Velvet Ant is a threat actor active since at least 2021, known for complex persistence mechanisms and targeting network devices and appliances using zero-day exploits. It employs TTPs such as execution via WMI and Unix Shell, persistence through RC Scripts, stealth via Process Injection, and uses PlugX malware along with Impacket. Defenders should monitor for anomalous authentication attempts on network appliances, Impacket usage, and signs of defense impairment like disabled tools or firewall modifications.
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.
Monitor execution of Windows Management Instrumentation and Unix Shell commands and detect anomalous script execution.
Monitor modifications to RC Scripts and logins to External Remote Services, detecting anomalous activity for persistence.
Monitor Process Injection and DLL Hijacking activities, detecting processes used for stealth.
Monitor network traffic and detect Network Sniffing activities, especially during transmission of sensitive information.
Monitor system network connections and file/directory discovery, detecting anomalous queries indicative of discovery activities.
Monitor SMB/Windows Admin Shares and Lateral Tool Transfer activities, detecting anomalous movements across the network.
Monitor network traffic and detect Internal Proxy and Data Encoding activities, especially for anomalous encoding schemes.
Monitor modifications or disabling of security tools and system firewall, detecting activities indicative of impaired defenses.
Velvet Ant uses RC Scripts for its persistence mechanism.
Velvet Ant uses the PlugX malware in its operations.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.