logo

Chinese hackers target Linux with new WolfsBane malware

ID: f854a9d4-a5d0-5f91-b806-c3f1a572f9ac

STIX ID: report--f854a9d4-a5d0-5f91-b806-c3f1a572f9ac

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-21

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

ESET researchers uncovered WolfsBane, a Linux backdoor attributed to the Gelsemium APT that uses a dropper, launcher, encrypted libraries and a modified BEURK userland rootkit for stealth and persistence, and FireWood, a related Linux backdoor potentially leveraging a kernel rootkit; both provide extensive C2-driven command execution, data exfiltration and long-term espionage capabilities, with IOCs published on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.