logo

Threat Bulletin: Fire in the Woods – A New Variant of FireWood

ID: 1617a17d-e3dc-56f5-97ed-c3da26db283a

STIX ID: report--1617a17d-e3dc-56f5-97ed-c3da26db283a

Feed Name: Intezer Blog

Threat Score
75/100

Date Published: 2025-08-13

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

Intezer researchers identified a new, low-detected variant of the FireWood Linux backdoor (RAT) that modifies startup sequencing, command set, persistence paths for root and non-root users, and connection logic while continuing to use kernel-level rootkit techniques and TEA-based communication; the report includes technical analysis, commands, persistence/file paths, and multiple SHA256 IOCs and notes a possible link to the long-running Project Wood/Gelsemium lineage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.