Velvet Ant — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 12, 2025
Last Seen
June 15, 2026

Velvet Ant is a apt_group tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed December 12, 2025; most recent activity June 15, 2026.

Related Threat Clusters

  • Operation Highland: Velvet Ant's Decade-Long Espionage Campaign

    Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…

    9 articles · Updated June 13, 2026
  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Payroll Pirate Campaign Targets Payroll Systems Using AiTM Session Hijacking

    The 'Payroll Pirate' campaign has emerged, utilizing advanced phishing and AiTM session hijacking to bypass MFA and reroute payroll disbursements. Targeting mid-market and enterprise organizations, attackers exploit…

    2 articles · Updated June 15, 2026
  • 2025 CWE Top 25 Most Dangerous Software Weaknesses Released

    The 2025 CWE Top 25 Most Dangerous Software Weaknesses list has been published, identifying critical vulnerabilities that pose significant risks to software security. This list is intended for developers and…

    10 articles · Updated December 11, 2025

Recent Intelligence Reports

  • Payroll Pirate Campaign Uses AiTM Session Hijacking to Bypass MFA and Redirect Salaries — Gbhackers · June 15, 2026
  • Chinese hackers hijack auth flow, spy on isolated network for a decade — Bleepingcomputer · June 13, 2026
  • Chinese hackers hijack auth flow, spy on isolated network for a decade — Bleepingcomputer · June 13, 2026
  • External Remote Services — attack.mitre.org · June 3, 2026
  • MITRE shares 2025's top 25 most dangerous software weaknesses — Bleepingcomputer · December 12, 2025

CVSS v3.1 Breakdown