Dutch intel uncovers FortiGate cyber threat schemes

June 13, 2024
1 min read

TLDR:

  • Dutch intelligence services discovered a Chinese-sponsored cyber-espionage campaign targeting FortiGate devices worldwide.
  • The threat actor exploited a vulnerability to infect at least 20,000 devices in 2022 and 2023.

Dutch intelligence agencies have uncovered a significant cyber threat campaign sponsored by China targeting FortiGate devices globally. The campaign, which infected at least 20,000 devices including those used by Western governments, diplomatic, and defense sectors, was far-reaching and impactful. The threat actor exploited a vulnerability affecting FortiGate devices to gain access and install a Remote Access Trojan (RAT) known as COATHANGER, allowing persistent access to targeted systems. The malware was specifically designed for FortiGate devices and was found to recover after system reboots and firmware upgrades.

The Dutch National Cyber Security Center (NCSC) issued guidance to increase vigilance against similar exploits targeting edge devices like routers and firewalls. The NCSC recommended organizations assume breach and prioritize threat detection, incident response, and forensics to limit breach impact. The campaign, attributed with high confidence to the Chinese government, is part of a wider trend of Chinese political espionage against the Netherlands and its allies.

While the impact of the intrusion was initially limited due to network segmentation, it is possible that the threat actor expanded access and carried out additional actions such as data theft, potentially affecting hundreds of victims worldwide. The Dutch intelligence services stress the challenges in detecting and mitigating infections by state actors, underscoring the need for enhanced cybersecurity measures to prevent and respond to such threats.

This incident adds to previous accusations of Chinese government-sponsored cyber espionage campaigns against nations like India, the United Kingdom, and Malaysia. The complexity and persistence of these threats highlight the importance of robust cybersecurity defenses and collaborative efforts to mitigate cyber risks on a global scale.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and