DFIR Tech Blog – an AI playground

Deutsch English
Foto von Tyler auf Unsplash.com

Operation Highland: A Decade of Espionage Inside Authentication Itself

03.08.2026 linux-forensikpam-backdoorair-gapchina-nexus-apt

When the Login Itself Belongs to the Attacker

Ten years. That’s how long the China-nexus espionage group Velvet Ant remained undetected inside an isolated, critical network belonging to a large organization, according to Sygnia’s research. The investigation, published in June 2026 under the name “Operation Highland,” reveals a methodology that renders classic containment playbooks largely useless: rather than relying on conventional malware or remote exploits, the attackers went straight for the authentication layer of the affected Linux systems.

The group had embedded itself in the authentication layer of Linux systems, replacing key PAM modules and OpenSSH binaries with altered versions that enabled continued access, credential theft, and command logging. Crucially, the entry point wasn’t the isolated segment itself: the campaign began in 2016, targeting vulnerable internet-facing systems before pivoting to an “air-gapped” environment with no direct internet connection.

Anatomy of an Attack on the Trust Foundation

What makes this case technically remarkable is the sheer scope of the manipulation. Sygnia identified nine distinct backdoored pam_unix.so variants compiled in separate build environments — these malicious PAM modules either accepted hardcoded backdoor passwords, harvested legitimate credentials to hidden stores, or performed both functions. Complementing the PAM tampering, Velvet Ant deployed multiple modified OpenSSH suites — malicious versions of ssh, sshd and scp performing credential dumping, encrypted command keylogging, SELinux disabling when executed as root, process disguising, and timestomping to erase forensic timelines.

Particularly relevant for investigators: the attackers actively managed their own forensic footprint. The group managed its own forensic footprint, including by using a custom flag in modified SSH binaries to prevent its activity from being logged. This didn’t just obscure the access itself — it deliberately undermined the classic forensic artifacts investigators rely on, namely SSH and auth logs. As a third, independent persistence layer, the attackers additionally appended their own public keys to the authorized_keys files on compromised servers, ensuring a fallback even if the tampered binaries were fully remediated.

The result was a complete compromise of the trust anchor itself: administrative activity became fully observable — every login, every command executed across compromised hosts. Access was no longer tied to a specific foothold but embedded into the authentication process itself. This meant persistence survived even password changes and session terminations — the very first-response measures IR teams typically reach for turned out to be completely ineffective.

Forensic Fallout: Cleaning Up Without Losing Your Own Access

Operation Highland illustrates why authentication-stack compromises belong in a fundamentally different category from routine malware findings. A standard “delete first, validate later” approach simply doesn’t work here: as long as the attacker controls authentication, any careless remediation step risks destroying the very access defenders need to continue the investigation and rebuild trust.

Compounding the challenge, Sygnia had to operate in a network without internet connectivity: most systems in the affected segment had no internet access, meaning defenders could not pull clean packages directly from trusted repositories or resolve dependencies live. The server estate also spanned multiple Linux distributions and versions, so replacement components had to be matched carefully to each host. The response was a methodical, staged process: Sygnia built a lab to test the recovery process in advance, then profiled each machine before remediation and immediately validated SSH and authentication health.

For DFIR practitioners, the case offers several concrete takeaways. File-integrity monitoring must treat PAM and OpenSSH binaries as prime attack surface rather than trusted infrastructure. Recommended mitigations include endpoint visibility (EDR) and telemetry relays for isolated networks, file-integrity monitoring focused on PAM and OpenSSH artifacts, strict privileged-access controls, vaulting credentials, disabling direct root SSH, and routing administration through hardened jump hosts with MFA enforced before reaching critical hosts. Equally critical: credential rotation must only happen after persistence has been fully eradicated — otherwise organizations simply rotate credentials straight back into the attacker’s hands.

Operation Highland is far more than another China-nexus case study. It’s a wake-up call for any forensics team that still treats network segmentation and air-gaps as sufficient control on their own — once the trust anchor itself is compromised, no amount of isolation prevents a decade of unnoticed espionage.

← Back to overview