ATT&CKSoftwareCOATHANGER

COATHANGER

S1105

Malware.View on attack.mitre.org

About this malware

COATHANGER is a remote access tool (RAT) targeting FortiGate networking appliances. First used in 2023 in targeted intrusions against military and government entities in the Netherlands along with other victims, COATHANGER was disclosed in early 2024, with a high confidence assessment linking this malware to a state-sponsored entity in the People's Republic of China. COATHANGER is delivered after gaining access to a FortiGate device, with in-the-wild observations linked to exploitation of CVE-2022-42475. The name COATHANGER is based on a unique string in the malware used to encrypt configuration files on disk: “She took his coat and hung it up”.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1014
Rootkit

COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.

T1027
Obfuscated Files or Information

COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`.

T1027.002
Software Packing

The first stage of COATHANGER is delivered as a packed file.

T1055
Process Injection

COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library.

T1057
Process Discovery

COATHANGER will query running process information to determine subsequent program execution flow.

T1059.004
Unix Shell

COATHANGER provides a BusyBox reverse shell for command and control.

T1070.004
File Deletion

COATHANGER removes files from victim environments following use in multiple instances.

T1071.001
Web Protocols

COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control.

T1083
File and Directory Discovery

COATHANGER will survey the contents of system files during installation.

T1095
Non-Application Layer Protocol

COATHANGER uses ICMP for transmitting configuration information to and from its command and control server.

T1140
Deobfuscate/Decode Files or Information

COATHANGER decodes configuration items from a bundled file for command and control activity.

T1190
Exploit Public-Facing Application

COATHANGER is installed following exploitation of a vulnerable FortiGate device.

T1222.002
Linux and Mac Permissions

COATHANGER will set the GID of `httpsd` to 90 when infected.

T1543.004
Launch Daemon

COATHANGER will create a daemon for timed check-ins with command and control infrastructure.

T1564.001
Hidden Files and Directories

COATHANGER creates and installs itself to a hidden installation directory.

View all 18 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. NCSC-NL COATHANGER Feb 2024 Open source
    Dutch Military Intelligence and Security Service (MIVD) & Dutch General Intelligence and Security Service (AIVD). (2024, February 6). Ministry of Defense of the Netherlands uncovers COATHANGER, a stealthy Chinese FortiGate RAT. Retrieved February 7, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.