BOLDMOVE
S1184 · Linux, Network Devices
BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs.
The record for BOLDMOVE only covers known Linux variants.
ATT&CK S1184
Sigma rules0
YARA rules0
Live IOCs0