Dutch Intelligence: Chinese Malware Coathanger Survives Firmware Patches, Hit 20,000 Edge Devices
Dutch intelligence agencies MIVD and AIVD published a joint advisory on October 7 warning that Chinese state-sponsored hackers are mass-exploiting edge devices. The Coathanger malware for Fortinet FortiGate compromised at least 20,000 appliances worldwide and persists through firmware upgrades.
- Coathanger exploited CVE-2022-42475, a FortiOS RCE rated CVSS 9.3
- At least 14,000 devices were hit during the zero-day window, 20,000 total
- The malware survives patching, reboots and firmware upgrades
- Agencies say Chinese actors obtained source code of targeted devices
Read next
Security