The Containment Era is here. →Explore

Executive Summary

In 2026, cybersecurity researchers uncovered 'Operation Highland,' a decade-long cyber-espionage campaign by the Chinese state-sponsored group Velvet Ant. Beginning in 2016, the attackers initially compromised internet-facing servers, deploying modified GS-Netcat reverse shells for encrypted remote access. They then installed custom SOCKS5 proxies to tunnel traffic, enabling access to isolated networks. By backdooring Linux Pluggable Authentication Modules (PAM) and OpenSSH components, Velvet Ant harvested credentials and maintained persistent access, effectively embedding themselves within the authentication process. This allowed them to monitor administrative activities and exfiltrate sensitive data undetected for ten years.

The discovery of this prolonged intrusion underscores the evolving sophistication of state-sponsored cyber threats. It highlights the critical need for organizations to implement robust monitoring of authentication systems, conduct regular integrity checks of security components, and adopt a zero-trust security model to mitigate the risk of such stealthy and persistent attacks.

Why This Matters Now

The revelation of Operation Highland emphasizes the urgent need for organizations to reassess and fortify their cybersecurity defenses, particularly focusing on authentication mechanisms and the integrity of security components. As state-sponsored cyber threats become more sophisticated and persistent, adopting a zero-trust security model and implementing continuous monitoring are essential to detect and prevent such long-term intrusions.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Operation Highland revealed significant vulnerabilities in authentication mechanisms and the lack of integrity monitoring for critical security components, highlighting the need for stringent compliance measures in these areas.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's lateral movement and data exfiltration, thereby reducing the overall blast radius.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit vulnerabilities in internet-facing servers may have been limited, reducing the likelihood of initial access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges through backdoored authentication modules could have been constrained, reducing the scope of unauthorized access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement through custom SOCKS5 proxies could have been limited, reducing their ability to access isolated network segments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control channels via modified Nginx configurations could have been constrained, reducing their ability to maintain remote execution.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate captured credentials and administrative data could have been limited, reducing the risk of data theft.

Impact (Mitigations)

The attacker's prolonged surveillance and data theft activities could have been constrained, reducing the overall impact of the breach.

Impact at a Glance

Affected Business Functions

  • Network Security
  • Authentication Services
  • System Administration
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of administrative credentials and sensitive network configurations.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit access to critical systems.
  • Deploy East-West Traffic Security controls to monitor and control internal network communications.
  • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Establish Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image