A suspected China-linked threat actor exploited CVE-2022-42475, a heap-based buffer overflow in Fortinet FortiOS SSL-VPN, as a zero-day to compromise internet-facing FortiGate devices in espionage operations. Reporting tied the activity to intrusions at a European government entity and an Africa-based managed service provider, with telemetry indicating exploitation began in October 2022, nearly two months before Fortinet released patches.
The attackers deployed a custom backdoor named BOLDMOVE, including a Linux variant designed specifically for FortiGate firewalls. Investigators said the malware could tamper with device logging to reduce visibility and help the operators evade detection, and assessed the tradecraft as consistent with prior Chinese campaigns targeting perimeter security infrastructure such as firewalls and IDS/IPS appliances for long-term intelligence collection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Mandiant telemetry indicated a suspected China-nexus threat actor was exploiting the FortiOS SSL-VPN vulnerability CVE-2022-42475 as early as October 2022. The espionage activity targeted at least a European government entity and an Africa-based managed service provider.
Metadata analysis cited by Mandiant showed Windows variants of the BOLDMOVE backdoor were compiled as early as 2021. The report noted no Windows BOLDMOVE samples were detected in the wild.
Mandiant reported that the zero-day exploitation involved deployment of the custom BOLDMOVE backdoor, including a Linux variant tailored for Fortinet FortiGate firewalls and designed to manipulate logging for evasion. The company assessed the tradecraft as consistent with prior Chinese espionage operations targeting internet-facing security devices.
Fortinet previously disclosed that unknown hacking groups had exploited CVE-2022-42475 to target governments and other large organizations. Fortinet said the attackers used a generic Linux implant capable of delivering additional payloads and executing remote commands.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.