COATHANGER

COATHANGERCOATHANGER

Description

Chinese FortiGate RAT. The COATHANGER malware is a remote access trojan (RAT) designed specifically for Fortigate appliances. It is used as second-stage malware, and does not exploit a new vulnerability. Intelligence services MIVD & AIVD refer to the malware as COATHANGER based on a string present in the code./nThe COATHANGER malware is stealthy and persistent. It hides itself by hooking system calls that could reveal its presence. It survives reboots and firmware upgrades./nMIVD & AIVD assess with high confidence that the malicious activity was conducted by a state-sponsored actor from the People’s Republic of China. This is part of a wider trend of Chinese political espionage against the Netherlands and its allies./nMIVD & AIVD assess that use of COATHANGER may be relatively targeted. The Chinese threat actor(s) scan for vulnerable edge devices at scale and gain access opportunistically, and likely introduce COATHANGER as a communication channel for select victims.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Cobian RAT
Software
htpRAT
Software
FALLCHILL
Software
GovRAT
Actor
RAZOR TIGER
Software
JadeRAT
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.