BOLDMOVE (ELF)
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 14:22:41
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of Fortinet's SSL-VPN (CVE-2022-42475). There is also a Windows variant.
Exploited vulnerabilities
- CVE-2022-42475 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Boldmove (report)
- ncsc.nl — Tlp Clear+Mivd+Aivd+Advisory+Coathanger (report)
- services.google.com — 01 Chinese Espionage Article M Trends 2024 (report)
- thehackernews.com — New Chinese Malware Spotted Exploiting (report)
- Mandiant — Chinese Actors Exploit Fortios Flaw (report)