NEW: Group Profiler — instant APT intel lookup. Try it →

Velvet Ant

Overview

Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.

Naming & attribution

Velvet Ant is tracked under 1 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here. Activity attributed since at least 2021.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1132 Data Encoding — used by 1 of 174 groups
  • T1211 Exploitation for Stealth — used by 2 of 174 groups
  • T1037.004 RC Scripts — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • INC Ransom — 7 shared techniques (18% overlap)
  • ToddyCat — 6 shared techniques (15% overlap)
  • APT41 China — 12 shared techniques (13% overlap)
  • Chimera China — 9 shared techniques (13% overlap)
  • APT32 Vietnam — 11 shared techniques (12% overlap)
  • FIN13 — 8 shared techniques (12% overlap)

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1211

TTPs — 22 techniques across 8 tactics

Tools & malware (2)

PlugX · Impacket

Reporting (2)