logo

Chinese APT Gelsemium Deploys 'Wolfsbane' Linux Variant

ID: b51e5b9b-371a-5e47-82dc-1798d88d7bff

STIX ID: report--b51e5b9b-371a-5e47-82dc-1798d88d7bff

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-11-21

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

The report describes Gelsemium-linked malware evolution: Wolfsbane (a Linux port of the Gelsevirine backdoor incorporating a Unix rootkit) and Firewood (a Linux backdoor with a kernel‑level rootkit derived from the long-running 'Project Wood') have been observed, with samples uploaded to VirusTotal and evidence that attackers exploit Java/Tomcat vulnerabilities to gain access. The article frames these findings within a broader surge in Linux-targeted attacks as adversaries build cross-platform tooling to target enterprise Linux servers and cloud infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.