TF-MAL-elf.boldmove
📛 Threat Title
Malware family: BOLDMOVE
Description
ThreatFox malware family `elf.boldmove`. Printable name: BOLDMOVE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.boldmove
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.boldmove
IOC database
- Type
- domain
- Value
elf.boldmove- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.boldmove
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.boldmove
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
BOLDMOVE is a type of backdoor malware written in C linked to People's Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices.
-
web:cloud.google.com
Mandiant identified a new malware we are tracking as " BOLDMOVE " as part of our investigation. We have uncovered a Windows variant of BOLDMOVE and a Linux variant, which is specifically designed to run on FortiGate Firewalls. We believe that this is the latest in a series of Chinese cyber espionage operations that have targeted internet-facing devices and we anticipate this tactic will ...
-
web:guardsix.com
The new malware instance " BOLDMOVE " is being attributed to Chinese Advanced Persistent Threat (APT) groups who are actively exploiting the vulnerability. ** Get research and analysis, insight, plus hints and tips, on how to mitigate BOLDMOVE in the main blog below. Head to the contents and click each section for quick navigation.
-
web:linuxsecurity.com
Alleged state-sponsored cybercriminals from China deployed unique malware to take advantage of a zero-day vulnerability in Fortinet systems, focusing on governmental infrastructures.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of Fortinet's SSL-VPN (CVE-2022-42475). There is also a Windows variant.
-
web:rhisac.org
Alleged Chinese Threat Actors Developing Fortinet Zero-Day Exploit for New " BOLDMOVE " Malware Campaign Targeting European and African Organizations Mandiant reported preparations for a campaign leveraging CVE-2022-42475, a vulnerability in Fortinet's FortiOS SSL-VPN, to target organizations in Europe and Africa with a new malware dubbed ...
-
web:socradar.io
The malware that Mandiant tracks as BoldMove is connected to the CVE-2022-42475 exploit, per their research. A European government agency and an African service have both been targets since October, and the malware was recognized in December 2022.
-
web:therecord.media
In January, Fortinet warned its customers that hackers were using this vulnerability to target government networks. Mandiant identified a sophisticated new malware , which the researchers dubbed Boldmove , that exploited this vulnerability. Boldmove's Linux variant was specifically designed to run on Fortinet's FortiGate firewalls.
-
web:www.bleepingcomputer.com
The new BOLDMOVE malware BOLDMOVE is a full-featured backdoor written in C that enables Chinese hackers to gain higher-level control over the device, with the Linux version specifically created to ...
-
web:www.darkreading.com
Attackers Crafted Custom Malware for Fortinet Zero-Day The " BoldMove " backdoor demonstrates a high level of knowledge of FortiOS, according to Mandiant researchers, who said the attacker appears ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.