Chinese APT Gelsemium Deploys 'Wolfsbane' Linux Variant
ID: b51e5b9b-371a-5e47-82dc-1798d88d7bff
STIX ID: report--b51e5b9b-371a-5e47-82dc-1798d88d7bff
Feed Name: Dark Reading
The report describes Gelsemium-linked malware evolution: Wolfsbane (a Linux port of the Gelsevirine backdoor incorporating a Unix rootkit) and Firewood (a Linux backdoor with a kernel‑level rootkit derived from the long-running 'Project Wood') have been observed, with samples uploaded to VirusTotal and evidence that attackers exploit Java/Tomcat vulnerabilities to gain access. The article frames these findings within a broader surge in Linux-targeted attacks as adversaries build cross-platform tooling to target enterprise Linux servers and cloud infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
