logo

Chinese Hackers Infiltrate Dutch Defense Networks with Coathanger RAT

ID: df80ed90-3529-57dd-aed8-c930af0c83c5

STIX ID: report--df80ed90-3529-57dd-aed8-c930af0c83c5

Feed Name: HackRead

Threat Score
88/100

Date Published: 2024-02-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Dutch intelligence warns that China-sponsored actors exploited a FortiGate zero-day (CVE-2022-42475) to install a FortiGate-tailored RAT called “Coathanger,” providing persistent SSL C2 access and enabling reconnaissance and exfiltration of Active Directory account data from segmented military networks; the intrusion was attributed to a PRC state-sponsored actor, impact was limited by network segmentation, and mitigations (patching, log analysis, limiting Internet access) were recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.