G1047 · ATT&CK 19.1 group
Velvet Ant
[Velvet Ant](https://attack.mitre.org/groups/G1047) is a threat actor operating since at least 2021. [Velvet Ant](https://attack.mitre.org/groups/G1047) is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.(Citation: Sygnia VelvetAnt 2024A)(Citation: Sygnia VelvetAnt 2024B)
Aliases: Velvet Ant
Mapped techniques (22)
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Prompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · topic-matchModule 13 — AI-assisted defense, RAG, agents, and MCP
Blue Team & Defensive Security · topic-matchModule 9 — AI-assisted offensive security and MCP
Red Team & Offensive Security · topic-matchModule 7 — Privilege, lateral movement, and controlled impact
Red Team & Offensive Security · topic-matchMemory-safety and low-level weakness classes
Vulnerability Research & Exploit Development · topic-matchStatic triage: strings, imports, resources, and capabilities
Malware Analysis & Reverse Engineering · topic-matchMemory forensics, injection, and resident behavior
Malware Analysis & Reverse Engineering · topic-matchModule 3 — Vulnerability discovery and validation
Red Team & Offensive Security · topic-matchMobile and Android vulnerability research
Vulnerability Research & Exploit Development · topic-matchHuman, workload, pipeline, and emergency identity
Cloud Security · topic-matchEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · topic-match
AI Security · topic-matchModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · topic-matchModule 13 — AI-assisted defense, RAG, agents, and MCP
Blue Team & Defensive Security · topic-matchModule 9 — AI-assisted offensive security and MCP
Red Team & Offensive Security · topic-matchModule 7 — Privilege, lateral movement, and controlled impact
Red Team & Offensive Security · topic-matchMemory-safety and low-level weakness classes
Vulnerability Research & Exploit Development · topic-matchStatic triage: strings, imports, resources, and capabilities
Malware Analysis & Reverse Engineering · topic-matchMemory forensics, injection, and resident behavior
Malware Analysis & Reverse Engineering · topic-matchModule 3 — Vulnerability discovery and validation
Red Team & Offensive Security · topic-matchMobile and Android vulnerability research
Vulnerability Research & Exploit Development · topic-matchHuman, workload, pipeline, and emergency identity
Cloud Security · topic-matchEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · topic-match