Chinese Coathanger malware hung out to dry by Dutch defense department
ID: b635860e-bf31-5433-868b-496f5362adf6
STIX ID: report--b635860e-bf31-5433-868b-496f5362adf6
Feed Name: The Register (Security)
Dutch intelligence agencies disclosed an espionage intrusion at the Ministry of Defense involving a previously unseen RAT called "Coathanger" that targets Fortinet FortiGate NGFWs via exploitation of CVE-2022-42475. The malware is highly stealthy, persists across reboots and firmware upgrades, hooks system calls to evade CLI detection, and was used for reconnaissance and AD account theft; authorities attribute the activity to Chinese state-sponsored actors with high confidence and published IOCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
