Velvet Ant: Chinese State-Sponsored Hackers Backdoored Linux Login for Nearly a Decade
Chinese state-sponsored threat actor 'Velvet Ant' is reported to have compromised Linux authentication infrastructure (PAM and OpenSSH) via a backdoor that persisted for approximately ten years, with trade media characterizing the target environment as air-gapped or isolated. Public coverage remains limited to a single trade-media report and a translated third-party blog, with no vendor or government CERT advisory, named affected entities, or insured losses disclosed.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Loss pathway centers on a long-dwell state-sponsored backdoor in widely deployed Linux authentication components, creating systemic cyber accumulation potential across organizations running Linux PAM/OpenSSH. The severity ceiling is currently bounded at medium because public evidence is limited to one trade-media report and one translation of a third-party blog: no authoritative vendor or CERT advisory has been published, no organizations are named, no exfiltration volume is quantified, and no claims activity is reported. Materiality remains medium pending corroboration through authoritative technical disclosure, government advisory, or evidence of broader active exploitation, which would also stress cyber attribution underwriting and war/cyber exclusion clauses.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialAffected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts