China’s Coathanger Malware: Over 20,000 FortiGate Systems Hacked in Massive Cyber Attack

The Netherlands’ cybersecurity agency reveals the Chinese state-sponsored Coathanger malware attack on the Ministry of Defense was far more extensive than initially thought. Around 14,000 FortiGate systems were compromised in a “zero-day period,” highlighting the rising threat to edge devices.

Hot Take:

The Netherlands’ Ministry of Defense just got schooled in cybersecurity 101 – courtesy of a “Coathanger” from China. Next time, maybe invest in some better hangers?

Key Points:

  • Attack by Chinese state-sponsored group targeted FortiGate devices.
  • 20,000 FortiGate systems compromised, mostly during a “zero-day period.”
  • Vulnerability: CVE-2022-42475, a critical buffer overflow bug in FortiOS SSL-VPN.
  • Attackers used “Coathanger” malware to maintain persistent access.
  • Many systems are still believed to be infected and controlled by attackers.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here