BOLDMOVE
MITRE ATT&CK: S1184 View on attack.mitre.org
Aliases: BOLDMOVE
- First seen
- 2022-11-28 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux, network-devices
- Profile updated
- 2026-07-07 15:31:44
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn
Context
BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs. The record for BOLDMOVE only covers known Linux variants.
Detection coverage
- 2 YARA rules
- 339 Sigma rules
Malware & tools used
- Unix Shell (attack-pattern)
- Ignore Process Interrupts (attack-pattern)
- Create or Modify System Process (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Compromise Host Software Binary (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- File Deletion (attack-pattern)
- Web Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Execution Guardrails (attack-pattern)
- Multi-hop Proxy (attack-pattern)
Exploited vulnerabilities
- CVE-2022-42475 (vulnerability)
Detection rules
- SEKOIA_Apt_Boldmove_Strings (yara-rule)
- MALPEDIA_Win_Boldmove_Auto (yara-rule)
Reports & references
- MITRE ATT&CK — S1184 (report)
- cloud.google.com — Chinese Actors Exploit Fortios Flaw (report)