China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Read full story on The Hacker News
Share
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
AI disclosure

Summary

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.