BOLDMOVE is a custom backdoor associated with suspected Chinese espionage activity and developed in both Windows and Linux variants. It is notable for a Linux build tailored for Fortinet FortiGate firewalls, including FortiOS environments compromised through exploitation of CVE-2022-42475. The malware has been linked to espionage intrusions against high-value organizations, including government and managed service provider targets, and reflects a broader pattern of China-nexus operators targeting edge devices that often have limited defensive visibility.
BOLDMOVE is written in C and provides a core remote-access feature set across variants. Documented capabilities include host reconnaissance, receipt of operator commands, remote shell execution, file operations including file removal, and traffic relaying from command-and-control infrastructure to follow-on systems. It uses the WolfSSL library to protect command-and-control communications with SSL/TLS.
The FortiGate-focused Linux variant includes platform-specific functionality intended to preserve access and reduce forensic visibility. Reported behaviors include disabling Fortinet logging daemons to evade detection, manipulating logging-related functionality, verifying execution from an expected path, and using a watchdog-style persistence mechanism that monitors a file for modification and replaces it with a trojanized version after backing up the legitimate file, likely to survive upgrades. The Linux variant also demonstrates knowledge of Fortinet-specific proprietary data formats, underscoring that it was engineered specifically for Fortinet environments rather than adapted from a generic Linux implant.
BOLDMOVE exemplifies the use of specialized malware on network security appliances to maintain stealthy long-term access after vulnerability exploitation. Its design emphasizes covert persistence, command execution, and use of compromised edge devices as relay points for deeper intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The intrusion vector in question relates to the exploitation of CVE-2022-42475, a heap-based buffer overflow vulnerability in FortiOS SSL-VPN that could result in unauthenticated remote code execution via specifically crafted requests. | The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE, a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls.
BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
"...exploit CVE-2022-42475, a vulnerability in Fortinet's FortiOS SSL-VPN."
Mandiant has observed a trend in which China-nexus attackers have gained access to edge devices via exploitation of vulnerabilities, particularly zero-days... If an attacker possesses an exploit for a zero-day vulnerability on these devices, they are often able to gain access to a target environment and remain undetected for an extended period of time.
Fortinet disclosed that unknown hacking groups have capitalized on the shortcoming to target governments and other large organizations with a generic Linux implant capable of delivering additional payloads and executing commands sent by a remote server.
A suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day... The intrusion vector in question relates to the exploitation of CVE-2022-42475, a heap-based buffer overflow vulnerability in FortiOS SSL-VPN that could result in unauthenticated remote code execution via specifically crafted requests.
This variant of BOLDMOVE disabled the `miglogd` and `syslogd` logging daemons on the appliance, and contained a command to patch memory address space for these logging functions.
APT5 'used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring'; BOLDMOVE 'can disable the Fortinet daemons moglogd and syslogd to evade detection and logging'; JumbledPath 'can impair logging on all devices used along its connection path'; Cutting Edge 'disabled logging'.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
At least two payloads of SystemBC ... communicated with that IP around 2023-10-27 ... Again, we found that this IP address resolved o*.*.claudfront[.]net on 2024-03-15 (see section in the main text dedicated to DecoyDog: DNS tunnelling as C2).
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
...allows attackers to perform file operations, spawn a remote shell, and relay traffic via the infected host.
BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems. Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments.
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.
...allows attackers to perform file operations, spawn a remote shell, and relay traffic via the infected host.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
Examples include Babuk 'can stop anti-virus services', BOLDMOVE disabling daemons, Conficker terminating services, Lazarus malware disabling Windows services, and SolarWinds Compromise where APT29 'used the service control manager on a remote system to disable services associated with security monitoring products.'
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware reportedly used in cyber espionage against vulnerable FortiOS devices; mentioned as background context.
A China-nexus backdoor tailored for Fortinet edge devices; it leverages device-native functionality and disables logging features to reduce visibility and extend attacker dwell time.
Implant/backdoor associated with Chinese threat actors, delivered via exploitation of Fortinet appliance vulnerabilities (including zero-days) to establish access on targeted devices.
BOLDMOVE is a backdoor designed for FortiGate Firewalls, deployed via exploitation of FortiOS vulnerabilities, enabling persistent access and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.