BOLDMOVE

S1184

Malware.View on attack.mitre.org

About this malware

BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023. BOLDMOVE includes both Windows and Linux variants, with some Linux variants specifically designed for FortiGate Firewall devices. BOLDMOVE is linked to zero-day exploitation of CVE-2022-42475 in FortiOSS SSL-VPNs. The record for BOLDMOVE only covers known Linux variants.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

BOLDMOVE enumerates network interfaces on the infected host.

T1059.004
Unix Shell

BOLDMOVE is capable of spawning a remote command shell.

T1070.004
File Deletion

BOLDMOVE can remove files on victim systems.

T1071.001
Web Protocols

BOLDMOVE uses web services for command and control communication.

T1082
System Information Discovery

BOLDMOVE performs system survey actions following initial execution.

T1083
File and Directory Discovery

BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory.

T1090.003
Multi-hop Proxy

BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.

T1190
Exploit Public-Facing Application

BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS.

T1480
Execution Guardrails

BOLDMOVE verifies it is executing from a specific path during execution.

T1543
Create or Modify System Process

BOLDMOVE can free all resources and terminate itself on victim machines.

T1554
Compromise Host Software Binary

BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades.

T1564.011
Ignore Process Interrupts

BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic.

T1573.002
Asymmetric Cryptography

BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication.

T1685
Disable or Modify Tools

BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Google Cloud BOLDMOVE 2023 Open source
    Scott Henderson, Cristiana Kittner, Sarah Hawley & Mark Lechtik, Google Cloud. (2023, January 19). Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475). Retrieved December 31, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.