Velvet Ant
Overview
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.
Naming & attribution
Velvet Ant is tracked under 1 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here. Activity attributed since at least 2021.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1132Data Encoding — used by 1 of 174 groups -
T1211Exploitation for Stealth — used by 2 of 174 groups -
T1037.004RC Scripts — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1211
TTPs — 22 techniques across 8 tactics
Execution
-
T1047Windows Management Instrumentation -
T1059.004Unix Shell -
T1569.002Service Execution
Persistence
-
T1037.004RC Scripts -
T1133External Remote Services
Stealth
-
T1036.005Match Legitimate Resource Name or Location -
T1055Process Injection -
T1078.003Local Accounts -
T1211Exploitation for Stealth -
T1574.001DLL
Defense Impairment
Credential Access
-
T1040Network Sniffing
Discovery
Lateral Movement
-
T1021.002SMB/Windows Admin Shares -
T1570Lateral Tool Transfer
Command and Control
-
T1071Application Layer Protocol -
T1090.001Internal Proxy -
T1132Data Encoding -
T1571Non-Standard Port -
T1573.002Asymmetric Cryptography
Tools & malware (2)
PlugX · Impacket