BOLDMOVE (Windows)

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:22:45

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to Mandiant, this malware family is attributed to potential chinese background and its Linux variant is related to exploitation of Fortinet's SSL-VPN (CVE-2022-42475).

Exploited vulnerabilities

  • CVE-2022-42475 (vulnerability)

Reports & references

  • thehackernews.com — New Chinese Malware Spotted Exploiting (report)
  • Mandiant — Chinese Actors Exploit Fortios Flaw (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Boldmove (report)

External references