COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.2
tool
COATHANGER S1105
- Type
- malware
- Platforms
- Linux, Network Devices
- Created
- 7 February 2024
- Last modified
- 15 April 2025
COATHANGER is a remote access tool (RAT) targeting FortiGate networking appliances. First used in 2023 in targeted intrusions against military and government entities in the Netherlands along with other victims, COATHANGER was disclosed in early 2024, with a high confidence assessment linking this malware to a state-sponsored entity in the People's Republic of China. COATHANGER is delivered after gaining access to a FortiGate device, with in-the-wild observations linked to exploitation of CVE-2022-42475. The name COATHANGER is based on a unique string in the malware used to encrypt configuration files on disk: “She took his coat and hung it up”.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1105
COATHANGER can store obfuscated configuration information in the last 56 bytes of the file /date/.bd.key/preload.so.3
The first stage of COATHANGER is delivered as a packed file.4
COATHANGER includes a binary labeled authd that can inject a library into a running process and then hook an existing function within that process with a new function from that library.5
COATHANGER will query running process information to determine subsequent program execution flow.6
COATHANGER provides a BusyBox reverse shell for command and control.7
Standing S1105
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
75th percentile · 75% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
80th percentile · 80% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
22nd percentile · 78% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1105
667 distinct rules cover the 18 techniques recorded for this tool. The 685 technique-to-rule mappings resolve to 667 distinct rules, because one rule can cover several techniques. 445 Sigma · 222 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org