EXECUTIVE SUMMARY:
Researchers have uncovered two Linux backdoors, WolfsBane and FireWood, within archives uploaded to VirusTotal. WolfsBane is confirmed to be the Linux version of Gelsemium’s Windows malware, Gelsevirine, marking a significant expansion of Gelsemium's toolset into Linux environments. FireWood shares characteristics with Project Wood, a backdoor used in Gelsemium’s Operation TooHash. However, its connection to Gelsemium remains inconclusive, as it might represent a shared resource among China-aligned APT groups. These backdoors underscore a growing trend of APTs leveraging Linux malware, likely due to heightened security measures on Windows platforms.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have uncovered two Linux backdoors, WolfsBane and FireWood, within archives uploaded to VirusTotal. WolfsBane is confirmed to be the Linux version of Gelsemium’s Windows malware, Gelsevirine, marking a significant expansion of Gelsemium's toolset into Linux environments. FireWood shares characteristics with Project Wood, a backdoor used in Gelsemium’s Operation TooHash. However, its connection to Gelsemium remains inconclusive, as it might represent a shared resource among China-aligned APT groups. These backdoors underscore a growing trend of APTs leveraging Linux malware, likely due to heightened security measures on Windows platforms.[emaillocker id="1283"]
WolfsBane, closely mirroring Gelsevirine, consists of a dropper, launcher, and backdoor. The dropper mimics legitimate tools and installs malware components in concealed directories, employing tactics like rootkits to evade detection. Its configuration, command execution mechanisms, and C&C communication exhibit strong overlaps with Windows Gelsevirine, cementing its attribution to Gelsemium. Conversely, FireWood exhibits code similarities with Project Wood, including shared encryption algorithms and naming conventions, but lacks definitive links to Gelsemium’s Linux arsenal. Both backdoors target Linux servers, employing techniques for persistence, data exfiltration, and command execution, with potential origins tied to web application vulnerabilities.
The discovery of WolfsBane and FireWood reflects an evolution in APT strategies, with Linux systems becoming prime targets. While WolfsBane's links to Gelsemium are robust, FireWood's attribution remains speculative, suggesting possible shared tools within a broader ecosystem of China-aligned groups. These findings emphasize the need for robust security practices across diverse operating systems, as adversaries continue to exploit gaps in server defenses and application vulnerabilities.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Resource Development | T1583 | Acquire Infrastructure |
| T1587 | Develop Capabilities | |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1037 | Boot or Logon Initialization Scripts |
| T1543 | Create or Modify System Process | |
| T1574 | Hijack Execution Flow | |
| T1547 | Boot or Logon Autostart Execution | |
| Privilege Escalation | T1546 | Event Triggered Execution |
| T1548 | Abuse Elevation Control Mechanism | |
| Defense Evasion | T1070 | Indicator Removal |
| T1564 | Hide Artifacts | |
| T1222 | File and Directory Permissions Modification | |
| T1027 | Obfuscated Files or Information | |
| T1014 | Rootkit | |
| T1036 | Masquerading | |
| Discovery | T1082 | System Information Discovery |
| T1083 | File and Directory Discovery | |
| Collection | T1056 | Input Capture |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/chinese-gelsemium-hackers-use-new-wolfsbane-linux-malware/