Threat Advisory

WolfsBane and FireWood Backdoors Linked to Gelsemium

Threat: Malware
Threat Actor Name: Gelsemium
Targeted Region: Eastern Asia, Middle East
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have uncovered two Linux backdoors, WolfsBane and FireWood, within archives uploaded to VirusTotal. WolfsBane is confirmed to be the Linux version of Gelsemium’s Windows malware, Gelsevirine, marking a significant expansion of Gelsemium's toolset into Linux environments. FireWood shares characteristics with Project Wood, a backdoor used in Gelsemium’s Operation TooHash. However, its connection to Gelsemium remains inconclusive, as it might represent a shared resource among China-aligned APT groups. These backdoors underscore a growing trend of APTs leveraging Linux malware, likely due to heightened security measures on Windows platforms.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have uncovered two Linux backdoors, WolfsBane and FireWood, within archives uploaded to VirusTotal. WolfsBane is confirmed to be the Linux version of Gelsemium’s Windows malware, Gelsevirine, marking a significant expansion of Gelsemium's toolset into Linux environments. FireWood shares characteristics with Project Wood, a backdoor used in Gelsemium’s Operation TooHash. However, its connection to Gelsemium remains inconclusive, as it might represent a shared resource among China-aligned APT groups. These backdoors underscore a growing trend of APTs leveraging Linux malware, likely due to heightened security measures on Windows platforms.[emaillocker id="1283"]

WolfsBane, closely mirroring Gelsevirine, consists of a dropper, launcher, and backdoor. The dropper mimics legitimate tools and installs malware components in concealed directories, employing tactics like rootkits to evade detection. Its configuration, command execution mechanisms, and C&C communication exhibit strong overlaps with Windows Gelsevirine, cementing its attribution to Gelsemium. Conversely, FireWood exhibits code similarities with Project Wood, including shared encryption algorithms and naming conventions, but lacks definitive links to Gelsemium’s Linux arsenal. Both backdoors target Linux servers, employing techniques for persistence, data exfiltration, and command execution, with potential origins tied to web application vulnerabilities.

The discovery of WolfsBane and FireWood reflects an evolution in APT strategies, with Linux systems becoming prime targets. While WolfsBane's links to Gelsemium are robust, FireWood's attribution remains speculative, suggesting possible shared tools within a broader ecosystem of China-aligned groups. These findings emphasize the need for robust security practices across diverse operating systems, as adversaries continue to exploit gaps in server defenses and application vulnerabilities.

THREAT PROFILE:

Tactic Technique Id Technique
Resource Development T1583 Acquire Infrastructure
T1587 Develop Capabilities
Execution T1059 Command and Scripting Interpreter
Persistence T1037 Boot or Logon Initialization Scripts
T1543 Create or Modify System Process
T1574 Hijack Execution Flow
T1547 Boot or Logon Autostart Execution
Privilege Escalation T1546 Event Triggered Execution
T1548 Abuse Elevation Control Mechanism
Defense Evasion T1070 Indicator Removal
T1564 Hide Artifacts
T1222 File and Directory Permissions Modification
T1027 Obfuscated Files or Information
T1014 Rootkit
T1036 Masquerading
Discovery T1082 System Information Discovery
T1083 File and Directory Discovery
Collection T1056 Input Capture
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/chinese-gelsemium-hackers-use-new-wolfsbane-linux-malware/

[/emaillocker]
crossmenu