Skip to content
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign

Operation Highland: Velvet Ant's Decade-Long Espionage Campaign

First seen 13 Jun 2026, 14:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 14, 2026 at 14:05 UTC

Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major organization's isolated network, allowing them full visibility into administrative activities. The intrusion started with the compromise of vulnerable internet-facing systems, followed by a pivot to an air-gapped environment. Velvet Ant exploited CVE-2024-20399, a zero-day vulnerability in Cisco NX-OS, and utilized a modified GS-Netcat reverse shell for remote access. The attackers established a remote execution path into the isolated network, enabling long-term persistence and credential theft. The campaign highlights the challenges of securing critical infrastructure against advanced persistent threats. Current status indicates ongoing investigations and heightened awareness of the threat posed by Velvet Ant.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2016-01-01
Operation Highland begins
Velvet Ant initiated its cyber-espionage campaign targeting vulnerable internet-facing systems.
Sygnia
2024-07-01
CVE-2024-20399 published
Cisco disclosed a zero-day vulnerability in NX-OS that Velvet Ant exploited for access.
BleepingComputer
2024-07-02
CVE-2024-20399 added to CISA KEV
CISA included the zero-day in its Known Exploited Vulnerabilities catalog due to active exploitation.
BleepingComputer
2024-07-03
First public PoC for CVE-2024-20399
A proof of concept for the Cisco NX-OS vulnerability was publicly released, detailing exploitation methods.
BleepingComputer
2026-06-13
Operation Highland details revealed
Sygnia published a detailed investigation into Velvet Ant's decade-long espionage campaign.
Sygnia

More articles in this cluster (9)

Following this threat?

Track Velvet Ant, GS-Netcat and CVE-2024-20399 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed