BOLDMOVE

MITRE ATT&CK: S1184 View on attack.mitre.org

Aliases: BOLDMOVE

First seen
2022-11-28 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
linux, network-devices
Profile updated
2026-07-07 15:31:44

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn

Context

BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs. The record for BOLDMOVE only covers known Linux variants.

Detection coverage

  • 2 YARA rules
  • 339 Sigma rules

Malware & tools used

  • Unix Shell (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • Create or Modify System Process (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • File Deletion (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Multi-hop Proxy (attack-pattern)

Exploited vulnerabilities

  • CVE-2022-42475 (vulnerability)

Detection rules

  • SEKOIA_Apt_Boldmove_Strings (yara-rule)
  • MALPEDIA_Win_Boldmove_Auto (yara-rule)

Reports & references

  • MITRE ATT&CK — S1184 (report)
  • cloud.google.com — Chinese Actors Exploit Fortios Flaw (report)

External references