Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware BOLDMOVE

BOLDMOVE

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

BOLDMOVE leverages a critical FortiOS SSL‑VPN vulnerability (CVE‑2022‑42475) to gain remote access to both Linux servers and specialized FortiGate firewall devices. After compromise it installs a persistent backdoor that can exfiltrate credentials, modify network policies, and pivot to internal hosts. This activity poses an acute risk to organizations using Fortinet infrastructure.

Enhanced Description

BOLDMOVE is a multi‑platform backdoor written largely in C and associated with state‑sponsored operations from the People’s Republic of China during 2022–2023. It ships as both Windows and Linux binaries, and several Linux versions are specially engineered to target FortiGate firewall platforms running FortiOS. Researchers trace BOLDMOVE's activity to a zero‑day exploitation of CVE‑2022‑42475, a critical flaw in FortiOS SSL‑VPN that allowed remote code execution on vulnerable devices. Once an attacker compromises a FortiGate appliance via the SSL‑VPN component, BOLDMOVE establishes persistent footholds by installing resident binaries and opening backdoor sockets listening for C&C traffic. The malware can exfiltrate credentials from local stores, manipulate firewall rules to open network entry points, and pivot into connected hosts over the internal network. In Linux hosts it offers a reverse shell interface, while on Windows systems it leverages native shell capabilities to issue commands. The limited public evidence indicates that BOLDMOVE primarily operates via exploitation of publicly exposed SSL‑VPN ports, followed by stealthy lateral movement and data collection. Because the backdoor is tailored for FortiGate devices, security teams protecting network perimeter appliances should be wary of unknown outbound connections originating from firmware processes post‑update or patching cycles.

Key Capabilities

  • Exploits the CVE‑2022‑42475 flaw in FortiOS SSL‑VPN for remote code execution
  • Installs a persistent backdoor on Linux, Windows, and FortiGate devices
  • Provides reverse shell access allowing command execution
  • Harvests local credentials and can modify firewall rules to create open channels
  • Facilitates lateral movement within internal networks

ATT&CK Techniques

T1190
T1059.001

Recommended Actions

  • Apply the latest firmware update that resolves CVE‑2022‑42475 to all FortiOS assets immediately.
  • Configure network IDS/IPS signatures for abnormal outbound traffic from Fortinet processes on ports 443 and 8443.
  • Patch all Linux servers against known vulnerabilities and remove any suspicious reverse shell binaries.
  • Conduct host integrity checks targeting the /opt/fortigate and related directories for unexpected executables.
  • Deploy endpoint detection solutions with heuristics for unknown C&C domain lookups and persistent service creation.

Suggested Tags

malware.backdoor
fortigate
cve-2022-42475
state-sponsored-malware
china-state-sponsor
ssl-vpn-exploit
remote-access-trojan

Confidence Assessment

Confidence in the core behavior description is moderate, drawing from public reports that confirm CVE exploitation and backdoor persistence on FortiGate devices. Gaps remain regarding detailed Windows functionality, full command & control infrastructure mapping, long‑term persistence mechanisms on Linux, and any post‑exploitation data exfiltration routes.

Description

BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs.(Citation: Google Cloud BOLDMOVE 2023) The record for BOLDMOVE only covers known Linux variants.

Details

Type
Malware
Platforms
Linux
Network devices
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.