VELVETTAP
VELVETTAP is a custom packet-capture tool used by the Velvet Ant threat actor on compromised F5 BIG-IP devices. The provided content identifies it specifically as tooling for passive network traffic collection on those devices. It appears in reporting on Velvet Ant’s broader post-compromise operations, which also included persistence via a modified /etc/rc.local file, command decoding and execution through the custom VELVETSTING tool, and communications over reverse SSH tunnels and encrypted channels. The activity associated with Velvet Ant spans F5 BIG-IP devices, Cisco switches, and Windows hosts, but VELVETTAP is specifically described only as a packet-capture capability on compromised F5 BIG-IP systems. No specific indicators of compromise for VELVETTAP are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Credential Access
1 techniqueDiscovery
1 techniqueRecent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom packet-capture tool used on compromised F5 BIG-IP devices for network sniffing.
Custom packet-capture tool used to collect traffic from compromised F5 BIG-IP devices.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.