Dutch intelligence agencies MIVD and AIVD identified a previously undisclosed remote-access trojan during an incident-response engagement that targeted FortiGate firewall appliances. The persistence-focused malware maintained covert access to compromised devices while seeking to evade conventional security controls; attackers gained initial access by exploiting CVE-2022-42475, a critical FortiOS SSL-VPN vulnerability.
The discovery underscores continued targeting of internet-facing edge infrastructure—including firewalls, VPN gateways, and email servers—where compromise can provide privileged access to internal networks. Organizations should promptly patch affected FortiGate systems, replace unsupported equipment, restrict and protect management interfaces, minimize internet exposure, and centralize device logging to improve detection and investigation capabilities.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The Dutch NCSC assessed CVE-2022-42475, a FortiGate vulnerability, as having high likelihood and high impact.
MIVD and AIVD identified a previously unknown remote-access trojan during an incident-response investigation. The targeted malware was designed to persist on FortiGate devices after attackers gained access, potentially through CVE-2022-42475 exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
mandiant.com
Open sourcencsc.nl
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.