Chinese Hackers Infiltrate Dutch Defense Networks with Coathanger RAT
ID: df80ed90-3529-57dd-aed8-c930af0c83c5
STIX ID: report--df80ed90-3529-57dd-aed8-c930af0c83c5
Feed Name: HackRead
Dutch intelligence warns that China-sponsored actors exploited a FortiGate zero-day (CVE-2022-42475) to install a FortiGate-tailored RAT called “Coathanger,” providing persistent SSL C2 access and enabling reconnaissance and exfiltration of Active Directory account data from segmented military networks; the intrusion was attributed to a PRC state-sponsored actor, impact was limited by network segmentation, and mitigations (patching, log analysis, limiting Internet access) were recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
