Security News > 2024 > February > Chinese hackers breached Dutch Ministry of Defense

Chinese state-sponsored hackers have breached the Dutch Ministry of Defense last year and deployed a new remote access trojan malware to serve as a backdoor.
"The effects of the intrusion were limited because the victim network was segmented from the wider MOD networks," the Dutch Military Intelligence and Security Service and the General Intelligence and Security Service noted.
A new RAT. During an investigation of a intrusion in the MOD's newtork last year, MIVD and AIVD uncovered a previously unknown malware that they named Coathanger.
"The name is derived from the peculiar phrase that the malware uses to encrypt the configuration on disk: 'She took his coat and hung it up'," MIVD and AIVD explained in the security advisory.
Coathanger is a remote access trojan that was specifically built for Fortinet's FortiGate appliances.
In this particular incident, hackers gained initial access to FortiGate devices by exploiting the critical FortiOS pre-auth RCE vulnerability, downloaded Coathanger, carried out reconnaissance of the network and managed to steal a list of user accounts from the Active Directory server.
News URL
https://www.helpnetsecurity.com/2024/02/07/chinese-hackers-dutch-mod/
Related news
- Chinese FamousSparrow hackers deploy upgraded malware in attacks (source)
- Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool (source)
- Chinese hackers target Russian govt with upgraded RAT malware (source)
- Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool (source)
- Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell (source)
- Chinese hackers behind attacks targeting SAP NetWeaver servers (source)
- Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization (source)