ATT&CKReferencesGoogle Cloud BOLDMOVE 2023

Google Cloud BOLDMOVE 2023

Scott Henderson, Cristiana Kittner, Sarah Hawley & Mark Lechtik, Google Cloud. (2023, January 19). Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475). Retrieved December 31, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBOLDMOVE

BOLDMOVE enumerates network interfaces on the infected host.

T1059.004
Unix Shell
MalwareBOLDMOVE

BOLDMOVE is capable of spawning a remote command shell.

T1070.004
File Deletion
MalwareBOLDMOVE

BOLDMOVE can remove files on victim systems.

T1071.001
Web Protocols
MalwareBOLDMOVE

BOLDMOVE uses web services for command and control communication.

T1082
System Information Discovery
MalwareBOLDMOVE

BOLDMOVE performs system survey actions following initial execution.

T1083
File and Directory Discovery
MalwareBOLDMOVE

BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory.

T1090.003
Multi-hop Proxy
MalwareBOLDMOVE

BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.

T1190
Exploit Public-Facing Application
MalwareBOLDMOVE

BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS.

T1480
Execution Guardrails
MalwareBOLDMOVE

BOLDMOVE verifies it is executing from a specific path during execution.

T1543
Create or Modify System Process
MalwareBOLDMOVE

BOLDMOVE can free all resources and terminate itself on victim machines.

T1554
Compromise Host Software Binary
MalwareBOLDMOVE

BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades.

T1564.011
Ignore Process Interrupts
MalwareBOLDMOVE

BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic.

T1573.002
Asymmetric Cryptography
MalwareBOLDMOVE

BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication.

T1685
Disable or Modify Tools
MalwareBOLDMOVE

BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.