🌐Velvet Ant
🌐 Velvet Ant is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: Unknown. We map 14 detection use cases to this actor across 22 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
22Techniques
0IOCs
About this actor (MITRE)
[Velvet Ant](https://attack.mitre.org/groups/G1047) is a threat actor operating since at least 2021. [Velvet Ant](https://attack.mitre.org/groups/G1047) is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.(Citation: Sygnia VelvetAnt 2024A)(Citation: Sygnia VelvetAnt 2024B)
Known aliases
Velvet Ant
Top techniques
All other tracked techniques
T1040 · Network SniffingT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1055 · Process InjectionT1059.004 · Unix ShellT1071 · Application Layer ProtocolT1078.003 · Local AccountsT1083 · File and Directory DiscoveryT1090.001 · Internal ProxyT1132 · Data EncodingT1133 · External Remote ServicesT1211 · Exploitation for StealthT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1571 · Non-Standard PortT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1685 · Disable or Modify ToolsT1686 · Disable or Modify System Firewall