Chinese hackers hijack auth flow, spy on isolated network for a decade
What happened
Researchers uncovered a decade‑long intrusion (Operation Highland) where attackers controlled an organization's authentication stack and tunneled into an isolated network. The report details custom PAM module variants, a SOCKS5 proxy, and web server configuration changes that show deep persistence across air‑gapped systems. Watch whether vendors supplying authentication components are audited or start issuing mitigations
Why the category manager should care
Do not assume isolation is sufficient; authentication tooling can be an entry and persistence vector and must be covered by contract evidence and testing
Key facts
- 10 years of persistence inside victim environment
- Multiple custom PAM module variants detected
- Attack chain included SOCKS5 proxy and web server forwarding