China Caught Dropping RAT Designed for FortiGate Devices
ID: 79a10471-b107-5094-bb44-7c7a78bd2610
STIX ID: report--79a10471-b107-5094-bb44-7c7a78bd2610
Feed Name: Dark Reading
Threat Score
Dutch military intelligence (MIVD) disclosed that Chinese state-aligned actors used a persistent remote access Trojan dubbed "Coathanger" in 2023 to spy on the Dutch Ministry of Defense by leveraging a known FortiGate vulnerability (CVE-2022-42475); the malware is stealthy, survives reboots and firmware upgrades, and forms part of a broader campaign scanning and exploiting Internet-facing edge devices such as firewalls, VPNs and mail servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
