20,000 FortiGate Systems Breached: Dutch Warn of Massive Chinese Cyber Espionage Campaign

Chinese hackers exploited a FortiOS/FortiProxy vulnerability to breach 20,000 FortiGate systems, impacting Western governments and defense companies. The Dutch Military Intelligence and Security Service (MIVD) revealed the scale of this cyber-espionage campaign, noting that the Coathanger malware used is difficult to detect and remove.

Hot Take:

Looks like the Chinese hackers have been playing hide and seek with our cybersecurity, and guess what? They’re winning. Who knew Fortigate devices were the ultimate playground for cyber-espionage? It’s like finding out your old teddy bear was a spy the whole time.

Key Points:

  • Chinese hackers exploited a critical FortiOS/FortiProxy vulnerability (CVE-2022-42475) to deploy malware.
  • The attack targeted 14,000 devices, including government and defense industry networks.
  • The Coathanger remote access trojan (RAT) malware was found on the Dutch Ministry of Defence network.
  • Hackers maintained access through firmware upgrades and system reboots.
  • At least 20,000 FortiGate systems were breached worldwide in 2022 and 2023.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here