Executive Summary
BOLDMOVE leverages a critical FortiOS SSL‑VPN vulnerability (CVE‑2022‑42475) to gain remote access to both Linux servers and specialized FortiGate firewall devices. After compromise it installs a persistent backdoor that can exfiltrate credentials, modify network policies, and pivot to internal hosts. This activity poses an acute risk to organizations using Fortinet infrastructure.
Enhanced Description
BOLDMOVE is a multi‑platform backdoor written largely in C and associated with state‑sponsored operations from the People’s Republic of China during 2022–2023. It ships as both Windows and Linux binaries, and several Linux versions are specially engineered to target FortiGate firewall platforms running FortiOS. Researchers trace BOLDMOVE's activity to a zero‑day exploitation of CVE‑2022‑42475, a critical flaw in FortiOS SSL‑VPN that allowed remote code execution on vulnerable devices. Once an attacker compromises a FortiGate appliance via the SSL‑VPN component, BOLDMOVE establishes persistent footholds by installing resident binaries and opening backdoor sockets listening for C&C traffic. The malware can exfiltrate credentials from local stores, manipulate firewall rules to open network entry points, and pivot into connected hosts over the internal network. In Linux hosts it offers a reverse shell interface, while on Windows systems it leverages native shell capabilities to issue commands. The limited public evidence indicates that BOLDMOVE primarily operates via exploitation of publicly exposed SSL‑VPN ports, followed by stealthy lateral movement and data collection. Because the backdoor is tailored for FortiGate devices, security teams protecting network perimeter appliances should be wary of unknown outbound connections originating from firmware processes post‑update or patching cycles.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core behavior description is moderate, drawing from public reports that confirm CVE exploitation and backdoor persistence on FortiGate devices. Gaps remain regarding detailed Windows functionality, full command & control infrastructure mapping, long‑term persistence mechanisms on Linux, and any post‑exploitation data exfiltration routes.
BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs.(Citation: Google Cloud BOLDMOVE 2023) The record for BOLDMOVE only covers known Linux variants.