www.sygnia.co Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
Article Content
- •Velvet Ant maintained a decade-long presence in a critical infrastructure network.
- •The attack exploited CVE-2024-20399 in Cisco NX-OS for initial access.
- •A modified GS-Netcat reverse shell was used to establish remote execution capabilities.
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major organization's isolated network, allowing them full visibility into administrative activities. The intrusion started with the compromise of vulnerable internet-facing systems, followed by a pivot to an air-gapped environment. Velvet Ant exploited CVE-2024-20399, a zero-day vulnerability in Cisco NX-OS, and utilized a modified GS-Netcat reverse shell for remote access. The attackers established a remote execution path into the isolated network, enabling long-term persistence and credential theft. The campaign highlights the challenges of securing critical infrastructure against advanced persistent threats. Current status indicates ongoing investigations and heightened awareness of the threat posed by Velvet Ant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Velvet Ant, GS-Netcat and CVE-2024-20399 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…