The Dutch Military Intelligence and Security Service (MIVD) has warned of a cyber espionage campaign by Chinese hackers, which was revealed earlier this year and targeted vulnerable Fortigate systems. Experts explained that the impact of the campaign was “much greater than we thought.”

Let's start from the beginning. In February, the MIVD, together with the General Intelligence and Security Service (AIVD), said that Chinese hackers exploited a critical FortiOS/FortiProxy vulnerability (CVE-2022-42475) within a few months between 2022 and 2023. The vulnerability allowed Chinese hackers to execute code remotely, with the aim of deploying malware on vulnerable security Fortigate network.
See also: Chinese hackers collaborate for cyber espionage
“ During this zero-day period, the attackers infected 14,000 devices. The targets included dozens of (Western) governments, international organizations and a large number of companies in the defense industry ,” the MIVD said
The malware that infected the systems was the Coathanger RAT, which was also detected on a Dutch Ministry of Defense network used for unclassified research and development (R&D) projects. However, due to the network's segmentation, the attackers were unable to move to other systems.
The MIVD found that this previously unknown malware, which could survive system reboots and firmware upgrades, was developed by state-run Chinese hackers for political espionage targeting the Netherlands and its allies.
“This gave the state agent permanent access to the systems. Even if a victim installs FortiGate security updates, the hackers continue to maintain this access,” the MIVD added.
The number of victims is not known, but experts believe the hackers could extend their access to hundreds of victims worldwide and do various things, such as steal data.
See also: Chinese hackers turn to ORB proxy networks

At least 20,000 Fortigate systems breached
Since February, the Dutch military intelligence agency discovered that the Chinese threat group gained access to at least 20,000 FortiGate systems worldwide in 2022 and 2023, at least two months before Fortinet disclosed the CVE-2022-42475 vulnerability.
The MIVD believes that Chinese hackers still have access to many FortiGate systems, given that the Coathanger malware is difficult to detect and resistant to updates.
See also: Chinese hackers breach networks through ScreenConnect and F5 BIG-IP vulnerabilities
The involvement of Chinese hackers in this attack adds another layer to the already complex cyber threat landscape facing organizations around the world. China-based threat actors have been linked to numerous high-profile attacks targeting governments, companies, and individuals.
The discovery of the FortiGate vulnerability and its exploitation by Chinese hackers serves as a reminder for organizations to remain vigilant in protecting their network security infrastructure. As cyber threats evolve at an alarming rate, it is imperative for companies to establish strong security measures and implement the latest security updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
