s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.firewood

📛 Threat Title

Malware family: FireWood

Category: FireWood First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.firewood`. Printable name: FireWood.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.firewood VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.firewood

IOC database

Type
domain
Value
elf.firewood
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.firewood

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.firewood

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    SUMMARY : A new, low-detected variant of the FireWood Linux backdoor has been discovered, showing changes in implementation and configuration while maintaining core functionality. This backdoor, linked to the 'Project Wood' malware lineage, operates as a remote access trojan on Linux systems, using kernel-level rootkit modules and TEA-based encryption for stealth and persistence. The new ...

  • web:cyberpress.org

    FireWood Linux Malware - Security researchers at Intezer have discovered a new, low-detected variant of the FireWood backdoor.

  • web:cybersecuritynews.com

    A sophisticated new variant of the FireWood backdoor has emerged, targeting Linux systems with enhanced evasion capabilities and streamlined command execution functionality. This latest iteration represents a significant evolution of the malware family first discovered by ESET's research team, which has been linked to the long-running "Project Wood" malware lineage dating back to at ...

  • web:gbhackers.com

    Intezer's Research Team has uncovered a new, low-detection variant of the FireWood backdoor, a sophisticated Linux-based remote access trojan (RAT) initially discovered by ESET researchers. Linked to the "Project Wood" malware lineage dating back to 2005, FireWood is associated with espionage campaigns like Operation TooHash and shows low-confidence ties to the China-aligned Gelsemium ...

  • web:hivepro.com

    Attack Details #1 Two sophisticated Linux backdoors are dicovered, WolfsBane and FireWood , both intricately tied to the Gelsemium APT group, a known player in cyberespionage. WolfsBane, a Linux variant of the Gelsevirine backdoor, and FireWood , an extension of the Project Wood backdoor. This shift towards Linux-focused malware signals a strategic pivot by threat actors, likely driven by ...

  • web:undercodenews.com

    Introduction: A Silent Evolution in Cyber Espionage Security researchers have uncovered a new and highly evasive variant of the notorious FireWood backdoor, a Linux malware family tied to espionage campaigns active for nearly two decades. First linked to cyber operations dating back to 2005, FireWood has repeatedly resurfaced with fresh capabilities designed to bypass detection and strengthen ...

  • web:www.broadcom.com

    A new variant of the Linux malware dubbed FireWood has been discovered in the wild. The malware is linked to Project Wood malware family and attributed to the Gelsemium APT group. FireWood backdoor has the capabilities to collect information about the infected machine, exfiltrate sensitive data as well as execute a number of commands received from the attackers. The observed functionalities of ...

  • web:www.infosecurity-magazine.com

    WolfsBane and FireWood Malware Tools Security researchers uncovered WolfsBane and FireWood as part of a sophisticated toolkit designed to compromise Linux environments. WolfsBane, attributed with high confidence to Gelsemium, serves as a stealthy loader designed to infiltrate targeted systems and enable the deployment of additional malware modules.

  • web:www.linkedin.com

    Linked to the "Project Wood" malware lineage dating back to 2005, FireWood is associated with espionage campaigns like Operation TooHash and shows low-confidence ties to the China-aligned ...

  • web:www.ryzome.com

    The following sections explore three evasive Linux malware strains discovered in 2024: Perfctl, WolfsBane, and FireWood . Understanding how these threats operate can help security teams assess their current security strategies and take the necessary steps to ensure their environments are adequately protected against Linux-targeted cyber attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.