logo

Chinese hackers breached 20,000 FortiGate systems worldwide

ID: 52e39349-83b0-5847-bc9b-8a44c9e3542e

STIX ID: report--52e39349-83b0-5847-bc9b-8a44c9e3542e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-06-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

The Dutch MIVD disclosed that a Chinese state-sponsored group exploited a FortiGate RCE (CVE-2022-42475) as a zero-day in 2022–2023 to deploy the persistent Coathanger RAT, compromising an estimated 14,000–20,000 devices worldwide and targeting Western governments, international organizations and defense industry entities; the implant can survive reboots and firmware upgrades, allowing sustained access even after patches are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.