ATT&CKGroupsVelvet Ant

Velvet Ant

G1047

Threat group.View on attack.mitre.org

About this group

Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

Velvet Ant has transferred tools within victim environments using SMB.

T1036.005
Match Legitimate Resource Name or Location

Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows.

T1037.004
RC Scripts

Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence.

T1040
Network Sniffing

Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.

T1047
Windows Management Instrumentation

Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI.

T1049
System Network Connections Discovery

Velvet Ant has enumerated existing network connections on victim devices.

T1055
Process Injection

Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them.

T1059.004
Unix Shell

Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell.

T1071
Application Layer Protocol

Velvet Ant has used reverse SSH tunnels to communicate to victim devices.

T1078.003
Local Accounts

Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.

T1083
File and Directory Discovery

Velvet Ant has enumerated local files and folders on victim devices.

T1090.001
Internal Proxy

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

T1132
Data Encoding

Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution.

T1133
External Remote Services

Velvet Ant has leveraged access to internet-facing remote services to compromise and retain access to victim environments.

T1211
Exploitation for Stealth

Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution.

View all 22 procedure examples

Software2

Campaigns0

None recorded.

References2

  1. Sygnia VelvetAnt 2024A Open source
    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.
  2. Sygnia VelvetAnt 2024B Open source
    Sygnia Team. (2024, July 1). China-Nexus Threat Group ‘Velvet Ant’ Exploits Cisco Zero-Day (CVE-2024-20399) to Compromise Nexus Switch Devices – Advisory for Mitigation and Response. Retrieved March 14, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.