logo

China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally

ID: 290af563-3107-5c95-9792-be3aed641a47

STIX ID: report--290af563-3107-5c95-9792-be3aed641a47

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-06-12

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

State-backed Chinese threat actors exploited a critical Fortinet FortiGate remote code execution vulnerability (CVE-2022-42475, CVSS 9.8) between 2022–2023 to compromise about 20,000 devices worldwide—infecting an estimated 14,000 during a zero-day period—and deployed a persistent backdoor named COATHANGER to maintain access, targeting Western governments, international organizations, and numerous defense-sector companies; the incident highlights the elevated risk from internet-facing edge appliances that often lack EDR protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.