TF-MAL-elf.firewood
📛 Threat Title
Malware family: FireWood
Description
ThreatFox malware family `elf.firewood`. Printable name: FireWood.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.firewood
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.firewood
IOC database
- Type
- domain
- Value
elf.firewood- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.firewood
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.firewood
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
SUMMARY : A new, low-detected variant of the FireWood Linux backdoor has been discovered, showing changes in implementation and configuration while maintaining core functionality. This backdoor, linked to the 'Project Wood' malware lineage, operates as a remote access trojan on Linux systems, using kernel-level rootkit modules and TEA-based encryption for stealth and persistence. The new ...
-
web:cyberpress.org
FireWood Linux Malware - Security researchers at Intezer have discovered a new, low-detected variant of the FireWood backdoor.
-
web:cybersecuritynews.com
A sophisticated new variant of the FireWood backdoor has emerged, targeting Linux systems with enhanced evasion capabilities and streamlined command execution functionality. This latest iteration represents a significant evolution of the malware family first discovered by ESET's research team, which has been linked to the long-running "Project Wood" malware lineage dating back to at ...
-
web:gbhackers.com
Intezer's Research Team has uncovered a new, low-detection variant of the FireWood backdoor, a sophisticated Linux-based remote access trojan (RAT) initially discovered by ESET researchers. Linked to the "Project Wood" malware lineage dating back to 2005, FireWood is associated with espionage campaigns like Operation TooHash and shows low-confidence ties to the China-aligned Gelsemium ...
-
web:hivepro.com
Attack Details #1 Two sophisticated Linux backdoors are dicovered, WolfsBane and FireWood , both intricately tied to the Gelsemium APT group, a known player in cyberespionage. WolfsBane, a Linux variant of the Gelsevirine backdoor, and FireWood , an extension of the Project Wood backdoor. This shift towards Linux-focused malware signals a strategic pivot by threat actors, likely driven by ...
-
web:undercodenews.com
Introduction: A Silent Evolution in Cyber Espionage Security researchers have uncovered a new and highly evasive variant of the notorious FireWood backdoor, a Linux malware family tied to espionage campaigns active for nearly two decades. First linked to cyber operations dating back to 2005, FireWood has repeatedly resurfaced with fresh capabilities designed to bypass detection and strengthen ...
-
web:www.broadcom.com
A new variant of the Linux malware dubbed FireWood has been discovered in the wild. The malware is linked to Project Wood malware family and attributed to the Gelsemium APT group. FireWood backdoor has the capabilities to collect information about the infected machine, exfiltrate sensitive data as well as execute a number of commands received from the attackers. The observed functionalities of ...
-
web:www.infosecurity-magazine.com
WolfsBane and FireWood Malware Tools Security researchers uncovered WolfsBane and FireWood as part of a sophisticated toolkit designed to compromise Linux environments. WolfsBane, attributed with high confidence to Gelsemium, serves as a stealthy loader designed to infiltrate targeted systems and enable the deployment of additional malware modules.
-
web:www.linkedin.com
Linked to the "Project Wood" malware lineage dating back to 2005, FireWood is associated with espionage campaigns like Operation TooHash and shows low-confidence ties to the China-aligned ...
-
web:www.ryzome.com
The following sections explore three evasive Linux malware strains discovered in 2024: Perfctl, WolfsBane, and FireWood . Understanding how these threats operate can help security teams assess their current security strategies and take the necessary steps to ensure their environments are adequately protected against Linux-targeted cyber attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.