---
title: "Chinese hackers hijack auth flow, spy on isolated network for a decade"
url: https://daily.dev/posts/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade-yeupuqtg0
source_url: https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade
type: article
source: "BleepingComputer"
published: 2026-06-13T14:12:04.649Z
updated: 2026-06-13T14:32:35.766Z
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Chinese hackers hijack auth flow, spy on isolated network for a decade

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 0 upvotes · 0 comments

## Summary

Chinese threat group Velvet Ant conducted a decade-long cyberespionage campaign (Operation Highland) against a large organization's air-gapped critical infrastructure network, starting in 2016. The attackers chained compromised internet-facing servers, a custom SOCKS5 proxy, modified Nginx configurations, and FastCGI execution bridges to reach the isolated network without a direct connection. Once inside, they replaced Linux PAM modules and OpenSSH components with backdoored versions that accepted hardcoded passwords, harvested credentials, and logged all administrative commands — effectively embedding persistence into the authentication layer itself. Nine distinct PAM module variants were identified, suggesting a well-resourced actor. Remediation was complex because removing the trojanized components risked breaking authentication entirely, requiring a dedicated test lab and rollback procedures. Defenders are advised to treat PAM, OpenSSH, and Windows LSASS as critical assets and protect them with EDR, file integrity monitoring, MFA, and immutable backups.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade>

## Similar posts on daily.dev

- [Chinese hackers breached critical infrastructure globally using enterprise network gear](https://daily.dev/posts/chinese-hackers-breached-critical-infrastructure-globally-using-enterprise-network-gear-vnoxze8g2) · CSO Online · 1 upvotes · 0 comments
- [Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using "Magic Packets"](https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci) · InfoSec Write-ups · 29 upvotes · 0 comments
- [From Log4j to IIS, China's Hackers Turn Legacy Bugs into Global Espionage Tools](https://daily.dev/posts/from-log4j-to-iis-china-s-hackers-turn-legacy-bugs-into-global-espionage-tools-woqwcbwos) · The Hacker News · 1 upvotes · 1 comments

---

[View this post on daily.dev](https://daily.dev/posts/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade-yeupuqtg0)
