HomeSecurityChinese Hackers Installed Hidden Backdoor in Linux Login Software for Almost a...

Chinese Hackers Installed Hidden Backdoor in Linux Login Software for Nearly a Decade

Instead of hiding in laptops and servers that researchers monitor more closely, a group of hackers linked to China spent nearly a decade hiding inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it installed backdoors in the PAM and OpenSSH components that decide who is allowed to log in, placing its access where regular sanitization couldn't reach.

See also: Outlook spying: Hackers were monitoring a stock exchange executive

Linux
Chinese Hackers Installed Hidden Backdoor in Linux Login Software for Nearly a Decade

The targeted network did not have direct internet access, so the team first used systems with internet access to get there. The first traces date back to 2016.

Instead of installing new malware that a scanner can detect, the attacker changed the trusted login programs. Nothing obvious appeared and no exploit was required, so the activity looked like normal administration. On several machines, the attacker replaced the primary PAM login module with backdoored copies. Some allowed them to log in with a secret password, while others silently recorded real usernames and passwords as users logged in.

The researchers found nine separate versions. The OpenSSH programs were modified in the same way, logging credentials and every command typed, with a hidden switch to disable this logging when needed. Accessing the isolated network required additional work.

The attacker used other camouflaged tools and an internet-facing web server as a bridge, passing commands through it to open remote sessions deep inside the department that had no direct internet access. Because the login system itself had been compromised, normal restrictive policies did little. Password resets and session terminations don't help when the system that controls those credentials is working for the attacker.

See also: WordPress: Hackers exploit Burst Statistics vulnerability

China-linked hackers - SecNews.gr
Chinese Hackers Installed Hidden Backdoor in Linux Login Software for Nearly a Decade

This is nothing new to the team. Whenever researchers find an access point, Velvet Ant moves to less monitored equipment and installs itself there. In a 2024 case, Sygnia found the same perpetrator turning internet-exposed F5 BIG-IP into internal command servers. Later that year, it reported the team exploiting a flaw in Cisco NX-OS, CVE-2024-20399, to install a backdoor on the switches.

This bug requires admin access first, so it’s a maintenance tool, not a remote exploit. Cisco patched it in July 2024, and CISA listed it as exploitable the next day. Operation Highland is the same idea, one layer deeper. Load balancers, switches, and the connection software itself are trusted by default and rarely checked, which is exactly why a patient attacker hides inside them.

Operation Highland is not a CVE problem. The attacker changed trusted programs after getting in, so the solution is verification, not repair, and cleanup is sensitive: a wrong replacement can lock administrators out of a live system.

  • Watch the connection files.
  • Monitor the PAM and OpenSSH programs and their core files for any changes and get notified when they change.
  • Hunt by checking what changed, not waiting for a notification.
  • Compare these programs with known good copies, because nothing will point them out to you.
  • Remove the backdoor before resetting the passwords, otherwise the new ones will be stolen in the same way.
  • Try any replacement first in a workshop.

See also: Hackers abuse Google Ads and Claude.ai chats for Mac attacks

China-linked hackers - SecNews.gr
Chinese Hackers Installed Hidden Backdoor in Linux Login Software for Nearly a Decade

The previous F5 and Cisco cases have their own checks: patch CVE-2024-20399 on Cisco Nexus equipment and monitor F5 devices for unexpected outbound connections. The broader lesson is clear: infrastructure outside of normal monitoring still needs integrity checks, and that now includes the connection layer.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS