Scott Henderson, Cristiana Kittner, Sarah Hawley & Mark Lechtik, Google Cloud. (2023, January 19). Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475). Retrieved December 31, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBOLDMOVE | BOLDMOVE enumerates network interfaces on the infected host. |
| T1059.004 Unix Shell |
MalwareBOLDMOVE | BOLDMOVE is capable of spawning a remote command shell. |
| T1070.004 File Deletion |
MalwareBOLDMOVE | BOLDMOVE can remove files on victim systems. |
| T1071.001 Web Protocols |
MalwareBOLDMOVE | BOLDMOVE uses web services for command and control communication. |
| T1082 System Information Discovery |
MalwareBOLDMOVE | BOLDMOVE performs system survey actions following initial execution. |
| T1083 File and Directory Discovery |
MalwareBOLDMOVE | BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory. |
| T1090.003 Multi-hop Proxy |
MalwareBOLDMOVE | BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems. |
| T1190 Exploit Public-Facing Application |
MalwareBOLDMOVE | BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS. |
| T1480 Execution Guardrails |
MalwareBOLDMOVE | BOLDMOVE verifies it is executing from a specific path during execution. |
| T1543 Create or Modify System Process |
MalwareBOLDMOVE | BOLDMOVE can free all resources and terminate itself on victim machines. |
| T1554 Compromise Host Software Binary |
MalwareBOLDMOVE | BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades. |
| T1564.011 Ignore Process Interrupts |
MalwareBOLDMOVE | BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic. |
| T1573.002 Asymmetric Cryptography |
MalwareBOLDMOVE | BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication. |
| T1685 Disable or Modify Tools |
MalwareBOLDMOVE | BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.