BOLDMOVE (ELF)

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:22:41

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of Fortinet's SSL-VPN (CVE-2022-42475). There is also a Windows variant.

Exploited vulnerabilities

  • CVE-2022-42475 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Boldmove (report)
  • ncsc.nl — Tlp Clear+Mivd+Aivd+Advisory+Coathanger (report)
  • services.google.com — 01 Chinese Espionage Article M Trends 2024 (report)
  • thehackernews.com — New Chinese Malware Spotted Exploiting (report)
  • Mandiant — Chinese Actors Exploit Fortios Flaw (report)

External references