China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Enterprise Linux infrastructure faces heightened APT risk as authentication bypass techniques target core system components rather than traditional endpoints.
Summary written by editorial AI · Source link below
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself.
Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no
Editorial Analysis
This demonstrates how APT groups are evolving to target foundational infrastructure components that security teams typically trust implicitly. Organizations need to reassess monitoring coverage of authentication systems.
Audit PAM and OpenSSH configurations for unauthorized modifications and implement integrity monitoring on authentication components.
Nation-state actors are compromising the foundation of enterprise Linux systems, requiring immediate infrastructure security review.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d