Home/Threat Actor/Velvet Ant
Threat Actor

Velvet Ant

velvet_ant · china · active since 2021-01

Velvet Ant (Sygnia canonical designation, June 17, 2024 first-disclosure) is a China-aligned cyber espionage cluster documented via Sygnia multi-year incident response engagement at an East Asian victim organization revealing approximately three years of persistent attacker dwell- time.

signature operational tradecraft is (1) systematic use of legacy F5 BIG-IP appliance persistence, compromised end-of-life F5 BIG-IP load balancer appliances retired from active production use but remaining reachable in victim network environments, providing multi-year persistent C2 footholds invisible to defender tooling focused on current production assets, and (2) sophisticated long-dwell- time espionage operational discipline complementing the broader documented China-aligned long-dwell pattern observed across Earth Estries (Demodex kernel rootkit), Salt Typhoon (US telecom long-dwell), and Volt Typhoon (preposition operations)

custom F5 BIG-IP-specific implants, PlugX and ShadowPad variants (shared Chinese-aligned tooling), Impacket, frp, EarthWorm, fscan, and Chinese- language webshells (Godzilla, Behinder, China Chopper); operationally distinct from but ecosystem-adjacent to all other Chinese-aligned clusters curated separately in this corpus.

china confidence: high 7 aliases MITRE ATT&CK G1047 ↗

Profile

Velvet Ant (Sygnia canonical designation, June 17, 2024 first-disclosure) is a China-aligned cyber espionage cluster canonically disclosed by Sygnia following a multi- year incident response engagement at an East Asian victim organization that revealed approximately three years of persistent attacker dwell-time in the victim environment. The Sygnia disclosure is operationally significant as a documented case study in long-dwell-time China-aligned espionage intrusion tradecraft. The cluster's operational distinctiveness is concentrated in two dimensions: (1) LEGACY F5 BIG-IP APPLIANCE PERSISTENCE OPERATIONAL SIGNATURE.

The Sygnia disclosure documented a signature tradecraft pattern of legacy F5 BIG-IP appliance persistence , Velvet Ant operators had compromised end-of-life F5 BIG-IP load balancer appliances that had been retired from active production use but remained reachable in the victim's network environment, and used these forgotten appliances as persistent C2 footholds invisible to defender tooling focused on current production assets. The legacy- appliance persistence pattern provided multi-year persistent C2 footholds invisible to defender vulnerability scanning, patching workflows, and endpoint detection tools that typically did not extend to retired appliances that were no longer included in production asset inventories. The operational tradecraft is significant for defender awareness: legacy appliance and forgotten-asset persistence represents a documented attack pattern with operational viability for long-dwell espionage operations.

(2) APPROXIMATELY THREE-YEAR PERSISTENT DWELL-TIME. The documented dwell-time duration is operationally consistent with state-aligned espionage operational priorities of sustained intelligence collection from high-value victim environments. The dwell-time duration is operationally distinct from cybercriminal ransomware operations (where dwell-time is typically measured in days to weeks before encryption deployment) and from less-resourced espionage operations.

The Velvet Ant case study operationally complements the broader documented China-aligned long-dwell- time espionage pattern observed across multiple clusters in this corpus including Earth Estries (earth_estries.yaml , long-dwell with Demodex kernel rootkit), Salt Typhoon (salt_typhoon.yaml, long-dwell against US telecoms), and Volt Typhoon (volt_typhoon.yaml, long-dwell preposition operations). Operational tradecraft includes systematic use of legacy F5 BIG-IP appliances for persistent foothold, deployment of custom F5 BIG-IP-specific implants engineered for the F5 appliance operating environment, extensive use of legitimate dual-use tooling (PlugX variants, ShadowPad, Impacket, fast reverse proxy / frp, EarthWorm, fscan) operationally consistent with Chinese-aligned cluster tooling adoption patterns, and sophisticated multi-tier proxy infrastructure for internal lateral movement and command-and-control resilience. Velvet Ant is operationally distinct from all other Chinese-aligned clusters curated separately in this corpus and fills the legacy-appliance-persistence / long-dwell- time-East-Asian-espionage cell in the curated Chinese- cluster coverage.

Aliases

7
velvet_antvelvet antvelvet ant operatorschina-aligned-velvet-ant-clusterf5-big-ip-legacy-persistence-clusterthree-year-dwell-time-china-clustervelvetant

Notable Campaigns

3
2024Sygnia Canonical Public Disclosure, Velvet Ant Three-Year Dwell-Time Intrusion (June 2024)
2021-2024Legacy F5 BIG-IP Appliance Persistence, Operational Signature Tradecraft
2021-2024China-Aligned Long-Dwell-Time Espionage Operations Case Study

Attribution & Reporting

Attributed by
SygniaMandiant (Google Threat Intelligence)Microsoft Threat IntelligenceCrowdStrikeRecorded FutureSymantec / Broadcom Threat Hunter TeamSentinelOneCISA (US Cybersecurity and Infrastructure Security Agency)Trend Micro
Key reporting
reportSygnia: China-Nexus Threat Group Velvet Ant (June 17, 2024), canonical first-disclosure
reportMandiant / Google Threat Intelligence: Velvet Ant China-Aligned Cluster Analysis
reportMicrosoft Threat Intelligence: Velvet Ant F5 BIG-IP Persistence Tradecraft Coverage
reportMalpedia Actor Profile: Velvet Ant

Operational

State sponsor

China-aligned cyber espionage cluster canonically disclosed by Sygnia in June 2024 following a multi-year incident response engagement at an East Asian victim organization that revealed approximately three years of persistent attacker dwell-time in the victim environment. Sygnia's attribution is based on operational tradecraft consistent with Chinese state-aligned cyber espionage operations (long-dwell persistent access, extensive custom tooling deployment, operational discipline consistent with state- aligned resourcing), targeting profile (East Asian victim organization with intelligence-value information assets), tooling overlap with broader Chinese-aligned cluster ecosystem (including ShadowPad and PlugX variants used by multiple Chinese-aligned clusters), infrastructure analysis, and operational tradecraft elements consistent with PRC state-aligned operations. The cluster has not been formally attributed by any government cybersecurity authority to a specific Chinese government agency, military unit (PLA SSF), or intelligence service (MSS).

The cluster is operationally distinct from the broader Chinese-aligned cluster ecosystem curated in this corpus including Volt Typhoon (volt_typhoon.yaml), Salt Typhoon (salt_typhoon.yaml), Silk Typhoon (silk_typhoon.yaml), Flax Typhoon (flax_typhoon.yaml), Storm-0558 (storm_0558.yaml), Earth Estries (earth_estries.yaml), TAG-100 (tag_100.yaml), GhostEmperor (ghostemperor.yaml), and the APT* China-aligned clusters (APT1, APT3, APT10, APT17, APT31, APT40, APT41), though all operate within the broader Chinese state-aligned cyber-operations ecosystem with some operational tradecraft overlaps.

Motivations
cyber_espionage, long_dwell_persistent_access_operations, intelligence_collection_for_chinese_state_priorities, east_asian_intelligence_collection, persistent_appliance_level_compromise
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin