Cyber Security News

Gelsemium APT Hackers Attacking Linux Servers With New WolfsBane Malware

A new Linux backdoor named WolfsBane has been recently uncovered by the ESET researchers, attributed to the Gelsemium advanced persistent threat (APT) group.

This discovery marks the first public report of Gelsemium using Linux malware, signaling a shift in their operational strategy. WolfsBane is identified as the Linux counterpart of Gelsevirine, a known Windows malware used by Gelsemium.

The malware’s primary goal is cyberespionage, targeting sensitive data such as system information, user credentials, and specific files and directories.

It is designed to maintain persistent access and execute commands stealthily, enabling prolonged intelligence gathering while evading detection.

Key Features of WolfsBane:-

  1. Custom libraries for network communication
  2. Sophisticated command execution mechanism
  3. Similar configuration structure to its Windows counterpart
  4. Use of previously known Gelsemium-associated domains

Alongside WolfsBane, researchers discovered another Linux backdoor named FireWood. While its connection to Gelsemium is less certain, it shares similarities with the group’s Project Wood malware.

FireWood’s attribution to Gelsemium is made with low confidence, considering it could be a tool shared among multiple China-aligned APT groups.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar

Attack Chain

The WolfsBane attack chain consists of three stages:

  1. Dropper: Disguised as a legitimate command scheduling tool, it places the launcher and backdoor in hidden directories.
  2. Launcher: Maintains persistence and initiates the backdoor.
  3. Backdoor: Loads embedded libraries for main functionalities and network communication.
WolfsBane execution chain (Source – Welivesecurity)

WolfsBane uses a modified open-source BEURK userland rootkit to hide its activities, hooking basic standard C library functions to filter out results related to the malware.

This discovery highlights a growing trend among APT groups to focus on Linux malware. This shift is attributed to:

  1. Improvements in Windows email and endpoint security
  2. Widespread use of endpoint detection and response (EDR) tools
  3. Microsoft’s decision to disable Visual Basic for Applications (VBA) macros by default

As a result, threat actors are increasingly targeting vulnerabilities in internet-facing systems, many of which run on Linux.

The emergence of WolfsBane and FireWood represents a significant evolution in Gelsemium’s tactics and the broader APT landscape.

As Linux systems become more attractive targets, organizations must adapt their security strategies to protect against these emerging threats.

This development underscores the need for comprehensive security measures across all operating systems and emphasizes the importance of staying vigilant against evolving cyber threats.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago