Malware.View on attack.mitre.org
BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs. The record for BOLDMOVE only covers known Linux variants.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
BOLDMOVE enumerates network interfaces on the infected host. |
| T1059.004 Unix Shell |
BOLDMOVE is capable of spawning a remote command shell. |
| T1070.004 File Deletion |
BOLDMOVE can remove files on victim systems. |
| T1071.001 Web Protocols |
BOLDMOVE uses web services for command and control communication. |
| T1082 System Information Discovery |
BOLDMOVE performs system survey actions following initial execution. |
| T1083 File and Directory Discovery |
BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory. |
| T1090.003 Multi-hop Proxy |
BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems. |
| T1190 Exploit Public-Facing Application |
BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS. |
| T1480 Execution Guardrails |
BOLDMOVE verifies it is executing from a specific path during execution. |
| T1543 Create or Modify System Process |
BOLDMOVE can free all resources and terminate itself on victim machines. |
| T1554 Compromise Host Software Binary |
BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades. |
| T1564.011 Ignore Process Interrupts |
BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic. |
| T1573.002 Asymmetric Cryptography |
BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication. |
| T1685 Disable or Modify Tools |
BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.