Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine
ID: 229da3e4-7fab-5586-a6fa-61b397cbac8b
STIX ID: report--229da3e4-7fab-5586-a6fa-61b397cbac8b
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers found and analyzed Linux backdoors (WolfsBane and FireWood) and related tools in VirusTotal-uploaded archives targeting web servers in East Asia; WolfsBane is attributed with high confidence to the China-aligned Gelsemium APT and includes a dropper, launcher, backdoor and a modified userland rootkit, while FireWood is linked to Project Wood with lower confidence. The report documents persistence mechanisms (systemd services, rc scripts, XDG autostart), C2 communication (UDP/HTTPS/TCP with TEA/RC4 encryption), credential theft (trojanized ssh client), webshells, kernel-module hiding, extensive IoCs, and mapped MITRE ATT&CK techniques to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
