Chinese hackers target Linux with new WolfsBane malware
ID: f854a9d4-a5d0-5f91-b806-c3f1a572f9ac
STIX ID: report--f854a9d4-a5d0-5f91-b806-c3f1a572f9ac
Feed Name: Bleeping Computer
Threat Score
ESET researchers uncovered WolfsBane, a Linux backdoor attributed to the Gelsemium APT that uses a dropper, launcher, encrypted libraries and a modified BEURK userland rootkit for stealth and persistence, and FireWood, a related Linux backdoor potentially leveraging a kernel rootkit; both provide extensive C2-driven command execution, data exfiltration and long-term espionage capabilities, with IOCs published on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
