Bernard Aybouts - Blog - Miltonmarketing.com

Approx. read time: 2.1 min.

Post: Chinese Cyber-Espionage Breaches Dutch Defence Networks with Persistent Malware

Chinese Cyber-Espionage Breaches Dutch Defence Networks with Persistent Malware. A cyber-espionage group from China infiltrated the Dutch Ministry of Defence’s network last year, introducing malware into the compromised systems, the Netherlands’ Military Intelligence and Security Service (MIVD) reported. Despite the successful breach and insertion of backdoors into the hacked systems, the impact was mitigated by the network’s segmentation.

The compromised network, isolated from the broader MOD networks, served fewer than 50 users focusing on research and development (R&D) of non-classified projects and engaged in partnerships with two external research institutes, all of which have been informed about the breach.

In the course of the investigation, an unknown type of malware, named Coathanger, a remote access trojan (RAT) targeting Fortigate network security appliances, was identified within the network. The COATHANGER malware is characterized by its persistence, capable of reinserting itself after system reboots and enduring through firmware updates. This persistence is achieved by embedding a backup within the system’s reboot process, posing a threat even to FortiGate devices that have been updated with the latest patches if they were compromised beforehand.

The malware ensures its concealment and continuous operation by intercepting system calls, thus remaining undetected, and is capable of maintaining its presence across system restarts and firmware updates.

While no specific group has been directly blamed for the attack, the MIVD attributes this incident to a Chinese state-backed hacking group with high certainty, indicating it as part of China’s broader strategy of political espionage against the Netherlands and its allies.

Chinese Cyber-Espionage Breaches Dutch Defence Networks with Persistent Malware

The hackers exploited a vulnerability in FortiGate firewalls, identified as CVE-2022-42475, to implant the Coathanger malware for espionage. This vulnerability had previously been used in targeted attacks against governmental entities and was disclosed by Fortinet in January 2023.

This incident mirrors other espionage campaigns by Chinese hackers, including attacks on unpatched SonicWall Secure Mobile Access (SMA) appliances with malware that also withstands firmware updates. Organizations are advised to promptly install vendor-released security updates for their internet-facing devices to avert similar threats.

This disclosure marks the first occasion the MIVD has publicly shared a technical report detailing the methods employed by Chinese hackers, as stated by Defense Minister Kajsa Ollongren. The aim is to attribute these espionage activities to China and bolster international defenses against such cyber espionage tactics.

Related Posts:

What is Healthcare Cybersecurity in organizations?

What Is Cybersecurity?

1.8 Million Users Attacked by Android Banking Malware, 300% Increase Since 2017

4 Important shifts companies need to make in this fast pace IT industry

The Longevity Blueprint: AI-Powered Health Optimization

Current step:1AI-Human Medical Analyzer: Smarter, Personalized Health
2AI-Human Medical Analyzer: Smarter, Personalized Health

> SYS.HEALTH: AI-Human Medical Analyzer_

// Revolutionize Your Diagnostics

Experience the perfect blend of cutting-edge AI precision and expert human care. Our revolutionary analyzer turns your raw health data into personalized, actionable insights tailored just for you.

> INITIALIZING_BIOMETRIC_SCAN...

[+] DATA_INPUT

Securely upload complex health parameters, including lab bloodwork and comprehensive medical history.

[+] PROCESSING

Advanced algorithmic parsing combined with human-level oversight ensures hyper-accurate data interpretation.

[+] OUTPUT_MATRIX

Receive smarter, faster, and truly personalized care strategies to take immediate charge of your health journey.

A name/nickname is required to continue.

> TRANSLATION_MATRIX_ACTIVE...
[ LANG_EN ]
Knowledge Heals, Prevention Protects
[ LANG_HI ]
ज्ञान ठीक करता है, रोकथाम सुरक्षा करती है
[ LANG_ZH ]
知识治愈,预防保护
[ LANG_JA ]
知識は癒し、予防は守る
[ LANG_HE ]
הידע מרפא, המניעה מגנה
[ LANG_AR ]
المعرفة تُشفي، والوقاية تحمي
[ LANG_FR ]
La connaissance guérit, la prévention protège

> SYS.AUTH: Data Processing Consent_

[ AWAITING_AUTHORIZATION ] By providing consent, you allow us to process your uploaded data through our proprietary AI-Human analysis system.

  • [+] SECURE_REVIEW: This ensures your information is carefully reviewed using advanced AI technology and certified professional oversight to deliver personalized health insights.
  • [+] PRIVACY_LOCK: Your privacy is our strict priority. Your data will only be used for this specific diagnostic purpose.

> SYS.UPLOAD: Share Medical Records [OPTIONAL]_

[ USER_CONTROL_ACTIVE ] Uploading your medical records during registration is entirely optional. You can choose to bypass this step and provide data later if it suits your timeline.

You dictate the data flow: share as much or as little as you’re comfortable with, and let us guide you toward better health.

[+] FORMAT_SUPPORT

We accept all file formats, including photos, PDFs, text documents, and raw official medical data.

[+] DATA_YIELD

Increased inputs correlate with higher precision. The more info you share, the better we tailor your personalized insights.

> NEXT_STEPS: Post-Registration Protocol_

Once your registration is complete, a human specialist from our team will personally reach out to you within 3-10 business days. We will discuss your health journey and map out exactly how we can support you.

About the Author: Bernard Aybout (Virii8)

Avatar Of Bernard Aybout (Virii8)
I am a dedicated technology enthusiast with over 45 years of life experience, passionate about computers, AI, emerging technologies, and their real-world impact. As the founder of my personal blog, MiltonMarketing.com, I explore how AI, health tech, engineering, finance, and other advanced fields leverage innovation—not as a replacement for human expertise, but as a tool to enhance it. My focus is on bridging the gap between cutting-edge technology and practical applications, ensuring ethical, responsible, and transformative use across industries. MiltonMarketing.com is more than just a tech blog—it's a growing platform for expert insights. We welcome qualified writers and industry professionals from IT, AI, healthcare, engineering, HVAC, automotive, finance, and beyond to contribute their knowledge. If you have expertise to share in how AI and technology shape industries while complementing human skills, join us in driving meaningful conversations about the future of innovation. 🚀