WolfsBane and FireWood: Gelsemium’s Expanding Arsenal Targets Linux Systems

Amber | Attack Report
Download PDF

A novel malware WolfsBane is linked to the Gelsemium APT group, as the Linux counterpart to their Windows-based Gelsevirine malware. Alongside this, a second backdoor called FireWood, tied to Project Wood, has also been identified, with its Windows variant previously deployed in Gelsemium’s Operation TooHash. Both backdoors demonstrate the group’s expanding cross-platform capabilities and sophisticated cyber-espionage strategies, underscoring the need for robust security measures to counter such advanced threats.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox