216.73.216.6

Unveiling WolfsBane: Linux counterpart to Gelsevirine

· Published 22/11/2024 04:49 · Modified 22/11/2024 09:25

Export JSON

Essential information

Published
22/11/2024 04:49
Modified
22/11/2024 09:25
Tags
2024-11-22 apt backdoor cyberespionage firewood gelsevirine linux persistence project wood rootkit wolfsbane
Related entities
41 observables, 1 intrusion sets (apt), 7 malware, 5 others

Description

ESET researchers have discovered previously unknown backdoors attributed to the China-aligned Gelsemium group. The main , named , is the equivalent of Gelsemium's for Windows. Another , , is connected to the group's malware. These tools are designed for , targeting system information, credentials, and specific files. The malware uses sophisticated techniques for , stealth, and command execution. This discovery marks Gelsemium's first known use of malware, indicating a shift in tactics towards exploiting vulnerabilities in internet-facing systems.

External references