s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.boldmove

📛 Threat Title

Malware family: BOLDMOVE

Category: BOLDMOVE First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.boldmove`. Printable name: BOLDMOVE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.boldmove VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.boldmove

IOC database

Type
domain
Value
elf.boldmove
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.boldmove

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.boldmove

References (1)

Remediations (10)

  • web:attack.mitre.org

    BOLDMOVE is a type of backdoor malware written in C linked to People's Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices.

  • web:cloud.google.com

    Mandiant identified a new malware we are tracking as " BOLDMOVE " as part of our investigation. We have uncovered a Windows variant of BOLDMOVE and a Linux variant, which is specifically designed to run on FortiGate Firewalls. We believe that this is the latest in a series of Chinese cyber espionage operations that have targeted internet-facing devices and we anticipate this tactic will ...

  • web:guardsix.com

    The new malware instance " BOLDMOVE " is being attributed to Chinese Advanced Persistent Threat (APT) groups who are actively exploiting the vulnerability. ** Get research and analysis, insight, plus hints and tips, on how to mitigate BOLDMOVE in the main blog below. Head to the contents and click each section for quick navigation.

  • web:linuxsecurity.com

    Alleged state-sponsored cybercriminals from China deployed unique malware to take advantage of a zero-day vulnerability in Fortinet systems, focusing on governmental infrastructures.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of Fortinet's SSL-VPN (CVE-2022-42475). There is also a Windows variant.

  • web:rhisac.org

    Alleged Chinese Threat Actors Developing Fortinet Zero-Day Exploit for New " BOLDMOVE " Malware Campaign Targeting European and African Organizations Mandiant reported preparations for a campaign leveraging CVE-2022-42475, a vulnerability in Fortinet's FortiOS SSL-VPN, to target organizations in Europe and Africa with a new malware dubbed ...

  • web:socradar.io

    The malware that Mandiant tracks as BoldMove is connected to the CVE-2022-42475 exploit, per their research. A European government agency and an African service have both been targets since October, and the malware was recognized in December 2022.

  • web:therecord.media

    In January, Fortinet warned its customers that hackers were using this vulnerability to target government networks. Mandiant identified a sophisticated new malware , which the researchers dubbed Boldmove , that exploited this vulnerability. Boldmove's Linux variant was specifically designed to run on Fortinet's FortiGate firewalls.

  • web:www.bleepingcomputer.com

    The new BOLDMOVE malware BOLDMOVE is a full-featured backdoor written in C that enables Chinese hackers to gain higher-level control over the device, with the Linux version specifically created to ...

  • web:www.darkreading.com

    Attackers Crafted Custom Malware for Fortinet Zero-Day The " BoldMove " backdoor demonstrates a high level of knowledge of FortiOS, according to Mandiant researchers, who said the attacker appears ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.